CVE-2023-44973: Malicious File Upload
Published Oct 3, 2023
·Updated
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected Software
1 affected component
Emlog emlog=2.2.0
Event History
Oct 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-44973.
2
What is the severity level of CVE-2023-44973?
CVE-2023-44973 has a severity level of critical (9.8).
3
What software versions are affected by CVE-2023-44973?
Emlog Pro v2.2.0 is affected by CVE-2023-44973.
4
How can attackers exploit CVE-2023-44973?
Attackers can exploit CVE-2023-44973 by uploading a crafted PHP file through /content/templates/ component, which allows them to execute arbitrary code.
5
Is there a fix available for CVE-2023-44973?
There is no information available about a fix for CVE-2023-44973. It is recommended to contact the software vendor for further guidance.