ZDI-CAN-21307: ZDI-23-1652: Adobe RoboHelp Server OnPublishFile Directory Traversal Remote Code Execution Vulnerability
Published Nov 15, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe RoboHelp Server. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2023-22273.
Affected Software
1 affected component
Adobe RoboHelp Server
Event History
Nov 15, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21307?
ZDI-CAN-21307 has been assigned a CVSS rating of 7.2, indicating high severity.
2
How do I fix ZDI-CAN-21307?
To fix ZDI-CAN-21307, apply the latest security patches provided by Adobe for RoboHelp Server.
3
What type of attack does ZDI-CAN-21307 allow?
ZDI-CAN-21307 allows remote attackers to execute arbitrary code on affected installations of Adobe RoboHelp Server.
4
Does ZDI-CAN-21307 require authentication to exploit?
Yes, ZDI-CAN-21307 requires authentication to exploit the vulnerability.
5
Which software is affected by ZDI-CAN-21307?
ZDI-CAN-21307 affects installations of Adobe RoboHelp Server.