CVE-2023-1484

A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. This issue affects some unknown processing of the file /api/upload. The manipulation of the argument uploadFile leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-223367.
CVSS

No CVSS.

Configurations

No configuration.

History

18 Mar 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-18 10:15

Updated : 2023-03-20 02:46


NVD link : CVE-2023-1484

Mitre link : CVE-2023-1484


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type