CVE-2023-0265: Malicious File Upload
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
Affected Software
Event History
Frequently Asked Questions
What is Uvdesk version 1.1.1?
Uvdesk version 1.1.1 is a software application that allows users to create and manage support tickets.
How does Uvdesk version 1.1.1 allow an attacker to execute commands on the server?
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands by exploiting a vulnerability in the validation of profile pictures uploaded by customers.
What is the severity of CVE-2023-0265?
The severity of CVE-2023-0265 is rated as high with a score of 8.8.
How can I fix the vulnerability in Uvdesk version 1.1.1?
To fix the vulnerability in Uvdesk version 1.1.1, it is recommended to update to a patched version provided by the software vendor.
Where can I find more information about CVE-2023-0265 and Uvdesk version 1.1.1?
You can find more information about CVE-2023-0265 and Uvdesk version 1.1.1 in the references provided: [Fluid Attacks Advisory](https://fluidattacks.com/advisories/supply/) and [Uvdesk Community-skeleton on GitHub](https://github.com/uvdesk/community-skeleton).