CVE-2023-44962: Malicious File Upload
Published Oct 11, 2023
·Updated
File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.
Affected Software
1 affected component
Koha-community Koha Library Software<=23.05.04
Event History
Oct 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-44962.
2
What is the severity of CVE-2023-44962?
The severity of CVE-2023-44962 is medium with a score of 5.3.
3
What is the affected software of CVE-2023-44962?
The affected software of CVE-2023-44962 is Koha Library Software version 23.05.04 and before.
4
How does the vulnerability CVE-2023-44962 work?
The vulnerability CVE-2023-44962 allows a remote attacker to read arbitrary files via the upload-cover-image.pl component in Koha Library Software.
5
Is there a fix for CVE-2023-44962?
A fix for CVE-2023-44962 is not available at the moment. It is recommended to follow the vendor's security advisories for updates.