CVE-2023-2419: Zhong Bang CRMEB SystemAttachmentServices.php videoUpload unrestricted upload
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argument filename leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227716.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2419?
CVE-2023-2419 has been declared as a critical severity vulnerability.
How do I fix CVE-2023-2419?
To fix CVE-2023-2419, it is recommended to update to the latest version of CRMEB that addresses this vulnerability.
What components of CRMEB are affected by CVE-2023-2419?
CVE-2023-2419 specifically affects the videoUpload function within the SystemAttachmentServices.php file.
What type of vulnerability is CVE-2023-2419?
CVE-2023-2419 is an unrestricted file upload vulnerability.
What should be done if CVE-2023-2419 is exploited?
If CVE-2023-2419 is exploited, immediate remediation is necessary to prevent data breaches and unauthorized access.