First published: Sun Jul 30 2023(Updated: )
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid On-Premises | <23.2.14 |
Update to version 23.2.14 b18 (On-Prem).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32225 is a vulnerability in Sysaid software that allows a malicious user with administrative privileges to upload a dangerous filetype.
CVE-2023-32225 has a severity score of 7.2, which is considered critical.
Sysaid On-premises version 23.2.14 and earlier is affected by CVE-2023-32225.
To fix CVE-2023-32225, it is recommended to update the Sysaid On-premises software to a version that addresses the vulnerability.
More information about CVE-2023-32225 can be found at this [link](https://www.gov.il/en/Departments/faq/cve_advisories).