Byzoro · Byzoro Smart S80 · CVE-2023-6274
**Name of the Vulnerable Software and Affected Versions**
Byzoro Smart S80 versions up to 20231108
Beijing Baichuo Smart S80 versions up to 20231108
**Description**
A critical issue affects an unknown functionality of the file /sysmanage/updatelib.php of the component PHP File Handler. The manipulation of the `file upload` argument leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
**Recommendations**
For Byzoro Smart S80 versions up to 20231108, consider disabling the `file upload` argument in the /sysmanage/updatelib.php file until a patch is available.
For Beijing Baichuo Smart S80 versions up to 20231108, consider disabling the `file upload` argument in the /sysmanage/updatelib.php file until a patch is available.
As a temporary workaround, restrict access to the /sysmanage/updatelib.php file to minimize the risk of exploitation.