Description
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.

Published: 2023-05-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-34176 Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.
History

Wed, 12 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Rental Module Project Rental Module
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2025-02-12T16:23:56.028Z

Reserved: 2023-05-15T13:58:02.132Z

Link: CVE-2023-2712

cve-icon Vulnrichment

Updated: 2024-08-02T06:33:05.540Z

cve-icon NVD

Status : Modified

Published: 2023-05-20T10:15:09.203

Modified: 2024-11-21T07:59:08.977

Link: CVE-2023-2712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses