CVE-2023-45724: Unauthenticated File Upload affects DRYiCE MyXalytics
Published Jan 3, 2024
·Updated
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.
Affected Software
3 affected components
hcltech Dryice Myxalytics=5.9
hcltech Dryice Myxalytics=6.0
hcltech Dryice Myxalytics=6.1
Event History
Jan 3, 2024
CVE Published
02:53 AM
Data Sourced
02:53 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45724?
CVE-2023-45724 is classified as a critical vulnerability due to the potential for unauthenticated file uploads.
2
How do I fix CVE-2023-45724?
To remediate CVE-2023-45724, it is essential to apply the latest security patches provided by HCL for affected versions of MyXalytics.
3
Which versions of HCL DRYiCE MyXalytics are affected by CVE-2023-45724?
CVE-2023-45724 affects HCL DRYiCE MyXalytics versions 5.9, 6.0, and 6.1.
4
What kind of attacks can exploit CVE-2023-45724?
CVE-2023-45724 can be exploited for malicious file uploads, potentially allowing attackers to execute arbitrary code on the server.
5
Is user authentication bypassed in CVE-2023-45724?
Yes, CVE-2023-45724 allows for unauthenticated file uploads, bypassing normal user authentication mechanisms.