First published: Mon Jan 13 2025(Updated: )
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Selesta Visual Access Manager | <4.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42248 is classified as a high severity vulnerability due to its potential for arbitrary file writing by authenticated attackers.
To fix CVE-2023-42248, upgrade to Selesta Visual Access Manager version 4.42.2 or later.
CVE-2023-42248 is a file write vulnerability that occurs through manipulation of POST parameters.
CVE-2023-42248 affects all versions of Selesta Visual Access Manager prior to 4.42.2.
No, CVE-2023-42248 requires an authenticated user to exploit the vulnerability.