An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
References
Link | Resource |
---|---|
http://www.w3.org/2000/svg | Not Applicable |
https://github.com/Volmarg | Not Applicable |
https://github.com/Volmarg/personal-management-system | Product |
https://github.com/Volmarg/personal-management-system/blob/39d3c0df641a5435f2028b37a27d26ba61a3b97b/src/assets/scripts/core/ui/DataProcessor/SpecialAction.ts#L35 | Vendor Advisory |
https://github.com/rootd4ddy/ | Not Applicable |
https://github.com/rootd4ddy/CVE-2023-43838 | Exploit Third Party Advisory |
http://www.w3.org/2000/svg | Not Applicable |
https://github.com/Volmarg | Not Applicable |
https://github.com/Volmarg/personal-management-system | Product |
https://github.com/Volmarg/personal-management-system/blob/39d3c0df641a5435f2028b37a27d26ba61a3b97b/src/assets/scripts/core/ui/DataProcessor/SpecialAction.ts#L35 | Vendor Advisory |
https://github.com/rootd4ddy/ | Not Applicable |
https://github.com/rootd4ddy/CVE-2023-43838 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:24
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.w3.org/2000/svg - Not Applicable | |
References | () https://github.com/Volmarg - Not Applicable | |
References | () https://github.com/Volmarg/personal-management-system - Product | |
References | () https://github.com/Volmarg/personal-management-system/blob/39d3c0df641a5435f2028b37a27d26ba61a3b97b/src/assets/scripts/core/ui/DataProcessor/SpecialAction.ts#L35 - Vendor Advisory | |
References | () https://github.com/rootd4ddy/ - Not Applicable | |
References | () https://github.com/rootd4ddy/CVE-2023-43838 - Exploit, Third Party Advisory |
06 Oct 2023, 16:14
Type | Values Removed | Values Added |
---|---|---|
First Time |
Personal-management-system
Personal-management-system personal Management System |
|
CWE | CWE-434 | |
References | (MISC) https://github.com/rootd4ddy/CVE-2023-43838 - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/Volmarg/personal-management-system - Product | |
References | (MISC) https://github.com/Volmarg/personal-management-system/blob/39d3c0df641a5435f2028b37a27d26ba61a3b97b/src/assets/scripts/core/ui/DataProcessor/SpecialAction.ts#L35 - Vendor Advisory | |
References | (MISC) https://github.com/rootd4ddy/ - Not Applicable | |
References | (MISC) http://www.w3.org/2000/svg - Not Applicable | |
References | (MISC) https://github.com/Volmarg - Not Applicable | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CPE | cpe:2.3:a:personal-management-system:personal_management_system:1.4.64:*:*:*:*:*:*:* |
04 Oct 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-04 16:15
Updated : 2024-11-21 08:24
NVD link : CVE-2023-43838
Mitre link : CVE-2023-43838
CVE.ORG link : CVE-2023-43838
JSON object : View
Products Affected
personal-management-system
- personal_management_system
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type