CVE-2023-3491: Unrestricted Upload of File with Dangerous Type in fossbilling/fossbilling
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
fossbilling/fossbillingto a version that resolves this vulnerability.Fixed in 0.5.3
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-3491.
What is the severity rating of CVE-2023-3491?
CVE-2023-3491 has a severity rating of 8.8 (high).
What is the affected software for CVE-2023-3491?
The affected software for CVE-2023-3491 is Fossbilling Fossbilling prior to version 0.5.3.
How can I fix CVE-2023-3491?
To fix CVE-2023-3491, update Fossbilling Fossbilling to version 0.5.3 or later.
Where can I find more information about CVE-2023-3491?
You can find more information about CVE-2023-3491 at the following links: [GitHub Commit](https://github.com/fossbilling/fossbilling/commit/2ddb7438ee0d05f9a9d01555edcfed820960f114) and [Huntr Bounty](https://huntr.dev/bounties/043bd900-ac78-44d2-a340-84ddd0bc4a1d).