PT-2023-20866 · Unknown · Onekeyadmin

Qbz95Aaa

·

Published

2023-03-06

·

Updated

2023-03-13

·

CVE-2023-26949

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions onekeyadmin version 1.3.9
Description The issue is related to an arbitrary file upload vulnerability in the /admin1/config/update component, allowing attackers to execute arbitrary code via a crafted PHP file.
Recommendations For onekeyadmin version 1.3.9, consider disabling the /admin1/config/update component until a patch is available to prevent arbitrary file uploads. Restrict access to this component to minimize the risk of exploitation. Avoid using this component to upload files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-26949

Affected Products

Onekeyadmin