PT-2023-5188 · Unknown · Qms Automotive
CVE-2023-40731
·
Publicado
2023-09-12
·
Atualizado
2023-09-14
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QMS Automotive versions prior to V12.39
Description
A vulnerability has been identified in the affected application, allowing users to upload arbitrary file types. This could allow an attacker to upload malicious files, potentially leading to code tampering. The vulnerability may be exploited by a remote attacker to execute arbitrary code by uploading a specially crafted file.
Recommendations
For versions prior to V12.39, consider restricting file uploads to only necessary and validated file types until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Qms Automotive