CVE-2023-41564: Malicious File Upload
Published Sep 8, 2023
·Updated
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
Other sources
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
Affected Software
2 affected components
composer/cockpit-hq/cockpit<=2.6.3
Agentejo Cockpit=2.6.3
Event History
Sep 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 9, 2023
Advisory Published
12:30 AM
Frequently Asked Questions
1
What is CVE-2023-41564?
CVE-2023-41564 is an arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3.
2
How does CVE-2023-41564 allow attackers to execute arbitrary code?
CVE-2023-41564 allows attackers to execute arbitrary code by uploading a crafted `.shtml` file.
3
Which version of Cockpit CMS is affected by CVE-2023-41564?
Cockpit CMS v2.6.3 is affected by CVE-2023-41564.
4
What is the severity rating of CVE-2023-41564?
CVE-2023-41564 has a severity rating of 6.1 (Medium).
5
How can I fix CVE-2023-41564?
To fix CVE-2023-41564, update Cockpit CMS to a version that does not have this vulnerability.