CVE-2023-23328: Malicious File Upload
Published Mar 10, 2023
·Updated
A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file.
Affected Software
1 affected component
AvantFAX AvantFAX=3.3.7
Event History
Mar 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23328?
CVE-2023-23328 has a medium severity level due to its impact on file uploads and potential exploitation.
2
How do I fix CVE-2023-23328?
To fix CVE-2023-23328, upgrade AvantFAX to version 3.3.8 or later to address the file upload vulnerability.
3
What type of vulnerability is CVE-2023-23328?
CVE-2023-23328 is classified as a File Upload vulnerability allowing bypass of PHP file type validation.
4
Who is affected by CVE-2023-23328?
Users of AvantFAX version 3.3.7 are affected by CVE-2023-23328.
5
What can attackers do with CVE-2023-23328?
Attackers can exploit CVE-2023-23328 to upload malicious PHP files, potentially compromising the server.