PT-2023-5188 · Unknown · Qms Automotive

CVE-2023-40731

·

Publicado

2023-09-12

·

Atualizado

2023-09-14

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QMS Automotive versions prior to V12.39
Description A vulnerability has been identified in the affected application, allowing users to upload arbitrary file types. This could allow an attacker to upload malicious files, potentially leading to code tampering. The vulnerability may be exploited by a remote attacker to execute arbitrary code by uploading a specially crafted file.
Recommendations For versions prior to V12.39, consider restricting file uploads to only necessary and validated file types until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05781
CVE-2023-40731

Produtos afetados

Qms Automotive