First published: Thu Jun 22 2023(Updated: )
funadmin v3.3.2 and v3.3.3 are vulnerable to insecure file upload via the plugins install.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Funadmin Funadmin | =3.3.2 | |
Funadmin Funadmin | =3.3.3 | |
composer/funadmin/funadmin | >=3.3.2<=3.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36097 is rated as a high severity vulnerability due to its potential for unauthorized file uploads.
To fix CVE-2023-36097, update Funadmin to version 3.3.4 or later to ensure secure file upload mechanisms are in place.
CVE-2023-36097 affects Funadmin versions 3.3.2 and 3.3.3.
CVE-2023-36097 is classified as an insecure file upload vulnerability that can lead to various security risks.
Yes, CVE-2023-36097 can be exploited remotely, enabling attackers to upload malicious files to the server.