Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Geekqd

#25694of 53,625
9.8Total CVSS
Vulnerabilities · 1
PT-2023-30927
9.8
2023-09-09
Beijing Baichuo · Beijing Baichuo Smart S45F Multi-Service Secure Gateway Intelligent Management Platform · CVE-2023-4873
**Name of the Vulnerable Software and Affected Versions** Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform versions up to 20230906 Beijing Baichuo Smart S45F Multi-Service Secure Gateway Intelligent Management Platform versions up to 20230906 **Description** A critical issue was found in the Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform, affecting an unknown function of the file /importexport.php. The manipulation of the `sql` argument leads to os command injection. This issue can be exploited remotely. **Recommendations** For Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform versions up to 20230906, consider restricting access to the /importexport.php file until a patch is available. For Beijing Baichuo Smart S45F Multi-Service Secure Gateway Intelligent Management Platform versions up to 20230906, avoid using the `sql` argument in the affected file /importexport.php until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.