First published: Thu Jan 26 2023(Updated: )
Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.
Credit: AFFAN AHMED security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Bumsys Project Bumsys | =1.0.0-beta | |
Bumsys Project Bumsys | =1.0.1 | |
Bumsys Project Bumsys | =1.0.2-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0455 is rated as high severity due to the risk of unrestricted file uploads leading to potential code execution.
To resolve CVE-2023-0455, upgrade to Bumsys version 1.0.3-beta or later, which addresses the vulnerability.
CVE-2023-0455 can facilitate attacks such as remote code execution or web shell installations through the upload of malicious files.
Versions 1.0.0-beta, 1.0.1, and 1.0.2-beta of Bumsys are affected by CVE-2023-0455.
Yes, there is a known exploit for CVE-2023-0455 that demonstrates the vulnerability through unrestricted file uploads.