Description
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Published: 2024-07-01
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update to MOTP 3.11.3 Patch 1 or later version or install the patch.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-31724 CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T19:32:42.884Z

Reserved: 2024-04-01T03:08:28.782Z

Link: CVE-2024-3123

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.884Z

cve-icon NVD

Status : Deferred

Published: 2024-07-01T05:15:04.973

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-3123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses