PT-2023-19466 · Unknown · Zhong Bang Crmeb

Keyman

·

Published

2023-04-29

·

Updated

2024-05-17

·

CVE-2023-2419

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zhong Bang CRMEB version 4.6.0
Description A critical issue affects the videoUpload function in the file SystemAttachmentServices.php, allowing unrestricted upload through manipulation of the filename argument. This can be initiated remotely. The issue has been publicly disclosed and may be exploited.
Recommendations For Zhong Bang CRMEB version 4.6.0, consider disabling the videoUpload function until a patch is available to prevent unrestricted file uploads. Restrict access to the SystemAttachmentServices.php file to minimize the risk of exploitation. Avoid using the filename argument in the affected function until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-2419

Affected Products

Zhong Bang Crmeb