PT-2023-6758 · Contec · Contec Solarview Compact

Atonysan

·

Published

2023-10-27

·

Updated

2024-09-12

·

CVE-2023-46509

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Contec SolarView Compact versions 6.0 and earlier
Description The issue is related to incorrect code generation management in the texteditor.php component of the Contec SolarView Compact software, which can allow an attacker to execute arbitrary code. This can be exploited by a remote attacker. The texteditor.php component is specifically mentioned as the vulnerable part of the software.
Recommendations For Contec SolarView Compact versions 6.0 and earlier, consider disabling the texteditor.php component as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2023-07549
CVE-2023-46509

Affected Products

Contec Solarview Compact