First published: Thu Jul 20 2023(Updated: )
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alkacon OpenCMS | =15.0.0 | |
maven/org.opencms:opencms-core | <=15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37602 is an arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 that allows attackers to execute arbitrary code via uploading a crafted PNG file.
CVE-2023-37602 has a severity rating of 6.1 (medium).
CVE-2023-37602 can be exploited by uploading a crafted PNG file to the /workplace#!explorer component of Alkacon OpenCMS v15.0.
The affected software for CVE-2023-37602 includes Alkacon OpenCMS v15.0.
There are currently no known fixes for CVE-2023-37602. It is recommended to update to a patched version or apply any necessary security patches provided by the vendor.