PT-2023-20744 · Idweb · Idweb

Jack Misiura

·

Published

2023-10-25

·

Updated

2023-10-28

·

CVE-2023-26578

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IDWeb application version 3.1.013
Description The issue allows authenticated attackers to upload arbitrary files to the web root, including dangerous files such as ASP or ASPX, which can lead to command execution on the affected server.
Recommendations For version 3.1.013, consider restricting access to the file upload functionality until a patch is available. As a temporary workaround, monitor the web root directory for suspicious files and remove them promptly to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-26578

Affected Products

Idweb