Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-37289

Опубликовано: 20 июл. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. This issue affects Document On-line Submission and Approval System: 22547, 22567.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:infodoc:document_on-line_submission_and_approval_system:22547:*:*:*:*:*:*:*
cpe:2.3:a:infodoc:document_on-line_submission_and_approval_system:22567:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00403
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker to exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. This issue affects Document On-line Submission and Approval System: 22547, 22567.

EPSS

Процентиль: 60%
0.00403
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434