PT-2023-22726 · Unknown · Tmt Lockcell

Efe Ozel

+5

·

Published

2023-06-13

·

Updated

2023-08-02

·

CVE-2023-3049

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TMT Lockcell versions prior to 15
Description The issue is related to an Unrestricted Upload of File with Dangerous Type vulnerability, which allows Command Injection in TMT Lockcell.
Recommendations For versions prior to 15, update to version 15 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent command injection until a patch is available.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-3049

Affected Products

Tmt Lockcell