PT-2023-25428 · Funadmin · Funadmin

Leeya_Bug

·

Published

2023-06-22

·

Updated

2023-06-28

·

CVE-2023-36097

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions funadmin versions 3.3.2 through 3.3.3
Description The issue concerns insecure file upload via the plugins install.
Recommendations For versions 3.3.2 and 3.3.3, consider disabling the plugins install feature until a patch is available. Restrict access to the plugins install module to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-36097
GHSA-5M3M-Q8CQ-77G4

Affected Products

Funadmin