First published: Tue Oct 17 2023(Updated: )
An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Expense Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44824 is a vulnerability in Expense Management System v.1.0 that allows a local attacker to execute arbitrary code via a crafted file upload.
The severity of CVE-2023-44824 is high (7.8).
CVE-2023-44824 affects Expense Management System v.1.0.
A local attacker can exploit CVE-2023-44824 by uploading a crafted file to the sign-up.php component.
Yes, here are some references for CVE-2023-44824: [reference 1](https://abstracted-howler-727.notion.site/CVE-2023-44824-ab76909b4a0e477b87aa8d0ca4aa4ca7), [reference 2](https://abstracted-howler-727.notion.site/Vulnerability-Description-ccc2e6489a0d43859c61a7982e649da1), [reference 3](https://gist.github.com/Muscial/e46c4e4031d25a3684cda124dfc45d96).