First published: Sat Mar 18 2023(Updated: )
A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. This issue affects some unknown processing of the file /api/upload. The manipulation of the argument uploadFile leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-223367.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xzjie Cms Project Xzjie Cms | <=1.0.3 | |
<=1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-1484 is critical.
CVE-2023-1484 affects xzjie cms up to version 1.0.3.
CVE-2023-1484 is an unrestricted upload vulnerability in xzjie cms up to version 1.0.3.
The impact of CVE-2023-1484 is the ability for an attacker to perform unrestricted file upload.
Yes, CVE-2023-1484 can be exploited remotely.