PT-2023-5188 · Unknown · Qms Automotive
Published
2023-09-12
·
Updated
2023-09-14
·
CVE-2023-40731
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QMS Automotive versions prior to V12.39
Description
A vulnerability has been identified in the affected application, allowing users to upload arbitrary file types. This could allow an attacker to upload malicious files, potentially leading to code tampering. The vulnerability may be exploited by a remote attacker to execute arbitrary code by uploading a specially crafted file.
Recommendations
For versions prior to V12.39, consider restricting file uploads to only necessary and validated file types until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qms Automotive