Description
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to MOTP 3.11.3 Patch 1 or later version or install the patch.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31724 | CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T19:32:42.884Z
Reserved: 2024-04-01T03:08:28.782Z
Link: CVE-2024-3123
Updated: 2024-08-01T19:32:42.884Z
Status : Deferred
Published: 2024-07-01T05:15:04.973
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-3123
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD