** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin 1.3.12. This issue affects the function Upload of the file application\admin\controller\Upload.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225407. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References
Link | Resource |
---|---|
https://tib36.github.io/2023/04/09/tpAdmin-RCE/ | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.225407 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.225407 | Third Party Advisory |
https://tib36.github.io/2023/04/09/tpAdmin-RCE/ | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.225407 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.225407 | Third Party Advisory |
Configurations
History
21 Nov 2024, 07:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://tib36.github.io/2023/04/09/tpAdmin-RCE/ - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.225407 - Permissions Required, Third Party Advisory | |
References | () https://vuldb.com/?id.225407 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 6.3 |
07 Nov 2023, 04:05
Type | Values Removed | Values Added |
---|---|---|
Summary | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin 1.3.12. This issue affects the function Upload of the file application\admin\controller\Upload.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225407. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. |
Information
Published : 2023-04-10 16:15
Updated : 2024-11-21 07:40
NVD link : CVE-2023-1970
Mitre link : CVE-2023-1970
CVE.ORG link : CVE-2023-1970
JSON object : View
Products Affected
tpadmin_project
- tpadmin
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type