CVE-2023-48394

CVSS V2 None CVSS V3 None
Description
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Overview
  • CVE ID
  • CVE-2023-48394
  • Assigner
  • twcert
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-12-15T09:25:18.105Z
  • Last Modified Date
  • 2024-01-17T07:23:51.933Z
References
History
Created Old Value New Value Data Type Notes
2024-06-24 23:48:54 Added to TrackCVE