HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-6973-45872-1.html | Third Party Advisory |
https://www.twcert.org.tw/tw/cp-132-6973-45872-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.twcert.org.tw/tw/cp-132-6973-45872-1.html - Third Party Advisory |
Information
Published : 2023-03-27 04:15
Updated : 2024-11-21 07:50
NVD link : CVE-2023-25909
Mitre link : CVE-2023-25909
CVE.ORG link : CVE-2023-25909
JSON object : View
Products Affected
hgiga
- oaklouds_portal
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type