First published: Thu Oct 26 2023(Updated: )
A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profil of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243601 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1-0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5795 is high, with a severity value of 8.8.
The affected software of CVE-2023-5795 is CodeAstro POS System 1.0.
CVE-2023-5795 is a vulnerability in CodeAstro POS System 1.0 that allows for unrestricted upload of profile pictures, potentially enabling remote attacks.
To exploit CVE-2023-5795, an attacker can upload malicious files as profile pictures, which can lead to remote code execution or other malicious activities.
To mitigate CVE-2023-5795, apply the latest patch or update provided by the vendor, and ensure that the file upload functionality restricts file types and performs proper validation.