CVE-2023-44824: Malicious File Upload
An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44824?
CVE-2023-44824 is a vulnerability in Expense Management System v.1.0 that allows a local attacker to execute arbitrary code via a crafted file upload.
What is the severity of CVE-2023-44824?
The severity of CVE-2023-44824 is high (7.8).
Which software version is affected by CVE-2023-44824?
CVE-2023-44824 affects Expense Management System v.1.0.
How can a local attacker exploit CVE-2023-44824?
A local attacker can exploit CVE-2023-44824 by uploading a crafted file to the sign-up.php component.
Are there any references for CVE-2023-44824?
Yes, here are some references for CVE-2023-44824: [reference 1](https://abstracted-howler-727.notion.site/CVE-2023-44824-ab76909b4a0e477b87aa8d0ca4aa4ca7), [reference 2](https://abstracted-howler-727.notion.site/Vulnerability-Description-ccc2e6489a0d43859c61a7982e649da1), [reference 3](https://gist.github.com/Muscial/e46c4e4031d25a3684cda124dfc45d96).