CVE-2023-2749: A Gain Information vulnerability was found on Download Center.
Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions. Download Center on ADM 4.0 and above will be affected. Affected products and versions include: Download Center 1.1.5.r1280 and below.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2749?
CVE-2023-2749 is a vulnerability in Asustor Download Center that allows an attacker to gain unauthorized access to sensitive files or directories.
Which products are affected by CVE-2023-2749?
Asustor Download Center versions up to and including 1.1.5.r1298 are affected.
What is the severity of CVE-2023-2749?
CVE-2023-2749 has a severity rating of 7.5, which is considered high.
How can an attacker exploit CVE-2023-2749?
An attacker can exploit CVE-2023-2749 by submitting a malicious file path to the Download Center, allowing them to gain unauthorized access to sensitive files or directories.
Is ASUSTOR ADM affected by CVE-2023-2749?
No, ASUSTOR ADM versions 4.1.0 and 4.2.0 are not affected by CVE-2023-2749.