First published: Sat Dec 16 2023(Updated: )
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php. The manipulation of the argument soffice leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.48.04 is able to address this issue. The identifier of the patch is 63a4d5708d210f119c24afd941d01a943e25334c. It is recommended to upgrade the affected component. The identifier VDB-248209 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kodcloud | <1.48.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6848 has been declared as critical severity.
To mitigate CVE-2023-6848, upgrade kodbox to version 1.48.04 or later.
CVE-2023-6848 is a command injection vulnerability.
CVE-2023-6848 affects kodbox versions up to 1.48.04.
CVE-2023-6848 occurs in the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php.