CVE-2023-39147: Malicious File Upload
Published Jul 31, 2023
·Updated
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
Credit
Daniel Barros
Affected Software
1 affected component
Webkul Uvdesk=1.1.3
Event History
Jul 31, 2023
Exploit Published
12:00 AM
Known Exploited
12:00 AM
Aug 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39147?
CVE-2023-39147 is an arbitrary file upload vulnerability in Uvdesk 1.1.3, allowing attackers to execute arbitrary code by uploading a crafted image file.
2
What is the severity of CVE-2023-39147?
The severity of CVE-2023-39147 is high, with a CVSS score of 7.8.
3
How can attackers exploit CVE-2023-39147?
Attackers can exploit CVE-2023-39147 by uploading a crafted image file, which allows them to execute arbitrary code.
4
Which version of Uvdesk is affected by CVE-2023-39147?
Uvdesk version 1.1.3 is affected by CVE-2023-39147.
5
Is there a fix for CVE-2023-39147?
Yes, ensure that you upgrade Uvdesk to a version that is not affected by CVE-2023-39147.