PT-2023-32789 · Kodbox · Kodbox

Glzjin

·

Published

2023-12-16

·

Updated

2024-05-17

·

CVE-2023-6848

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kalcaddle kodbox versions up to 1.48
Description A critical issue has been found, affecting the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php. The manipulation of the soffice argument leads to command injection. This issue can be exploited remotely.
Recommendations For versions up to 1.48, upgrade to version 1.48.04 to address this issue. As a temporary workaround, consider restricting access to the plugins/officeViewer/controller/libreOffice/index.class.php file until the upgrade is applied.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-6848

Affected Products

Kodbox