CVE-2023-50982: Malicious File Upload
Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because uploadaction and editaction in AdminSmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50982?
CVE-2023-50982 is a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2023-50982?
To fix CVE-2023-50982, upgrade to version 5.3.4 or later of Stud.IP.
What types of attacks can CVE-2023-50982 enable?
CVE-2023-50982 can enable cross-site scripting (XSS) attacks that lead to remote code execution.
Which versions of Stud.IP are affected by CVE-2023-50982?
Versions 5.x through 5.3.3 of Stud.IP are affected by CVE-2023-50982.
What is the impact of CVE-2023-50982?
The impact of CVE-2023-50982 includes the ability for attackers to execute arbitrary code with the privileges of the www-data user.