CVE-2023-44974: Malicious File Upload
Published Oct 3, 2023
·Updated
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected Software
1 affected component
Emlog emlog=2.2.0
Event History
Oct 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-44974?
The severity of CVE-2023-44974 is critical with a severity value of 9.8.
2
How does the arbitrary file upload vulnerability in Emlog Pro v2.2.0 work?
The vulnerability allows attackers to execute arbitrary code by uploading a crafted PHP file through the /admin/plugin.php component.
3
Which version of Emlog Pro is affected by CVE-2023-44974?
CVE-2023-44974 affects Emlog Pro v2.2.0.
4
How can I fix the arbitrary file upload vulnerability in Emlog Pro v2.2.0?
To fix the vulnerability, you should update Emlog Pro to a version that has addressed the issue.
5
Is there any additional reference for CVE-2023-44974?
Yes, you can find more information about the vulnerability at the following link: [https://github.com/yangliukk/emlog/blob/main/Plugin-getshell.md](https://github.com/yangliukk/emlog/blob/main/Plugin-getshell.md).