CVE-2023-45554: Malicious File Upload
Published Oct 24, 2023
·Updated
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.
Affected Software
1 affected component
ZZZCMS ZZZCMS=2.1.9
Event History
Oct 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-45554.
2
What is the severity of CVE-2023-45554?
The severity of CVE-2023-45554 is critical with a CVSS score of 9.8.
3
Which software version is affected by CVE-2023-45554?
The version affected by CVE-2023-45554 is zzzCMS v.2.1.9.
4
How does CVE-2023-45554 work?
CVE-2023-45554 is a file upload vulnerability that allows a remote attacker to execute arbitrary code by modifying the imageext parameter.
5
Is there a fix available for CVE-2023-45554?
Currently, there is no known fix available for CVE-2023-45554. It is recommended to update to a patched version or apply a security patch when it becomes available.