File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.
References
Configurations
No configuration.
History
21 Nov 2024, 07:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/rodnt/90ac26fdf891e602f6f090d6aebce32d - |
01 Aug 2024, 13:43
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
27 Jun 2024, 12:47
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 Jun 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-26 20:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-26877
Mitre link : CVE-2023-26877
CVE.ORG link : CVE-2023-26877
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')