PT-2023-20744 · Idweb · Idweb
Jack Misiura
·
Published
2023-10-25
·
Updated
2023-10-28
·
CVE-2023-26578
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IDWeb application version 3.1.013
Description
The issue allows authenticated attackers to upload arbitrary files to the web root, including dangerous files such as ASP or ASPX, which can lead to command execution on the affected server.
Recommendations
For version 3.1.013, consider restricting access to the file upload functionality until a patch is available. As a temporary workaround, monitor the web root directory for suspicious files and remove them promptly to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Idweb