PT-2023-32227 · Arslansoft · Arslansoft Education Portal

Published

2023-12-01

·

Updated

2026-05-20

·

CVE-2023-5636

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ArslanSoft Education Portal versions prior to v1.1
Description The issue allows Command Injection due to an Unrestricted Upload of File with Dangerous Type vulnerability.
Recommendations For versions prior to v1.1, update to version v1.1 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent potential Command Injection attacks.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-5636

Affected Products

Arslansoft Education Portal