Typecho · Typecho · CVE-2023-36299
**Name of the Vulnerable Software and Affected Versions**
typecho version 1.2.1
**Description**
A File Upload issue allows a remote attacker to execute arbitrary code via the `upload` and `options-general` parameters in "index.php".
**Recommendations**
For typecho version 1.2.1, as a temporary workaround, consider restricting access to the "index.php" endpoint and limiting the use of the `upload` and `options-general` parameters until a patch is available.