First published: Thu Sep 28 2023(Updated: )
A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash book entry. Afterwards, the attacker may visit the web shell and execute arbitrary commands.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/gugoan/economizzer | <=0.9-beta1 | |
Economizzer | =0.9-beta1 | |
Economizzer | =april_2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38874 is a remote code execution (RCE) vulnerability in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023) that allows an attacker to upload a PHP web shell through an insecure file upload functionality.
CVE-2023-38874 allows a malicious attacker to upload a PHP web shell as an attachment when adding a new cash book entry in gugoan's Economizzer, and then visit the web shell to execute arbitrary code.
The severity of CVE-2023-38874 is classified as high, as it allows remote code execution, which can lead to unauthorized access and control of the affected system.
To fix CVE-2023-38874, it is recommended to update to the latest version of gugoan's Economizzer and apply any available patches or security updates.
More information about CVE-2023-38874 can be found on the GitHub page dedicated to vulnerability research as well as the GitHub repository and the official website of gugoan's Economizzer.