PT-2023-27218 · Unknown · Yak Engine
Villanch
·
Published
2023-08-14
·
Updated
2024-08-21
·
CVE-2023-40023
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Yak Engine versions prior to 1.2.4-sp1
Description
The Yak Engine contains a local file inclusion (LFI) vulnerability, allowing attackers to include files from the server's local file system through the web application. This can lead to unintended exposure of sensitive data, potential remote code execution, or other security breaches.
Recommendations
For versions prior to 1.2.4-sp1, upgrade to version 1.2.4-sp1 to patch the vulnerability. If upgrading is not possible, avoid exposing vulnerable versions to untrusted input and closely monitor any unexpected server behavior until an upgrade can be performed. As a temporary workaround, consider restricting access to sensitive files and closely monitoring server behavior to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yak Engine