Description
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 2_1_0_23 or latest version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52446 | Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7624-d0300-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-02T21:30:34.805Z
Reserved: 2023-11-16T04:08:17.029Z
Link: CVE-2023-48394
No data.
Status : Modified
Published: 2023-12-15T10:15:08.237
Modified: 2024-11-21T08:31:37.730
Link: CVE-2023-48394
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD