PT-2023-21914 · Unknown · Wade Graphic Design Fantsy

Dio Lin

+2

·

Published

2023-06-02

·

Updated

2023-06-09

·

CVE-2023-28699

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wade Graphic Design FANTSY (affected versions not specified)
Description The issue is related to insufficient filtering for file type in the file update function. An authenticated remote attacker with general user privilege can exploit this to upload a PHP file containing a webshell, allowing for arbitrary system operation or service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-28699

Affected Products

Wade Graphic Design Fantsy