First published: Tue May 16 2023(Updated: )
A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-229149 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tongda2000 Tongda Oa | =11.10 | |
=11.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Tongda OA vulnerability is CVE-2023-2738.
The severity of CVE-2023-2738 is classified as critical.
Tongda OA version 11.10 is affected by CVE-2023-2738.
The vulnerability in GatewayController.php allows for unrestricted upload, posing a critical security risk to Tongda OA.
Yes, the exploit for CVE-2023-2738 has been disclosed to the public.