PT-2023-27218 · Unknown · Yak Engine

Villanch

·

Publicado

2023-08-14

·

Atualizado

2024-08-21

·

CVE-2023-40023

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yak Engine versions prior to 1.2.4-sp1
Description The Yak Engine contains a local file inclusion (LFI) vulnerability, allowing attackers to include files from the server's local file system through the web application. This can lead to unintended exposure of sensitive data, potential remote code execution, or other security breaches.
Recommendations For versions prior to 1.2.4-sp1, upgrade to version 1.2.4-sp1 to patch the vulnerability. If upgrading is not possible, avoid exposing vulnerable versions to untrusted input and closely monitor any unexpected server behavior until an upgrade can be performed. As a temporary workaround, consider restricting access to sensitive files and closely monitoring server behavior to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40023
GHSA-XVHG-W6QC-M3QQ
GO-2023-2011

Produtos afetados

Yak Engine