PT-2024-12118 · Softexpert · Softexpert Excellence Suite

Published

2024-06-26

·

Updated

2024-08-01

·

CVE-2023-26877

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Softexpert Excellence Suite version 2.1
Description A file upload issue allows attackers to execute arbitrary code by uploading a .php file to the "form/efms exec html/file upload parser.php" endpoint.
Recommendations For Softexpert Excellence Suite version 2.1, consider disabling the file upload functionality to the "form/efms exec html/file upload parser.php" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using this endpoint for uploading files, especially .php files, until the issue is resolved.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-26877

Affected Products

Softexpert Excellence Suite