PT-2023-25545 · Unknown · Pos Codekop

Yudha P

·

Published

2023-06-23

·

Updated

2023-07-04

·

CVE-2023-36348

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions POS Codekop version 2.0
Description The issue is related to an authenticated remote code execution (RCE) vulnerability. It can be exploited via the filename parameter.
Recommendations For POS Codekop version 2.0, consider restricting access to the filename parameter to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-36348

Affected Products

Pos Codekop