First published: Mon Jul 31 2023(Updated: )
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
Credit: Daniel Barros cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webkul Uvdesk | =1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39147 is an arbitrary file upload vulnerability in Uvdesk 1.1.3, allowing attackers to execute arbitrary code by uploading a crafted image file.
The severity of CVE-2023-39147 is high, with a CVSS score of 7.8.
Attackers can exploit CVE-2023-39147 by uploading a crafted image file, which allows them to execute arbitrary code.
Uvdesk version 1.1.3 is affected by CVE-2023-39147.
Yes, ensure that you upgrade Uvdesk to a version that is not affected by CVE-2023-39147.