PT-2023-29814 · Unknown · Thingnario Photon

CVE-2023-46055

·

Published

2023-10-21

·

Updated

2024-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThingNario Photon version 1.0
Description An issue in the software allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping function at the "thingnario Logger Maintenance Webpage" endpoint.
Recommendations For ThingNario Photon version 1.0, consider disabling access to the "thingnario Logger Maintenance Webpage" endpoint until a patch is available. As a temporary workaround, restrict the use of the ping function to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46055

Affected Products

Thingnario Photon