CVE-2023-46694

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.
Configurations

No configuration.

History

21 Nov 2024, 08:29

Type Values Removed Values Added
References () https://github.com/invisiblebyte/CVE-2023-46694 - () https://github.com/invisiblebyte/CVE-2023-46694 -

03 Jul 2024, 01:42

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

29 May 2024, 13:02

Type Values Removed Values Added
Summary
  • (es) Vtenext 21.02 permite a un atacante autenticado cargar archivos arbitrarios, lo que potencialmente le permite ejecutar comandos remotos. Esta falla existe debido a que la aplicación no aplica los controles de autenticación adecuados al acceder a la funcionalidad del administrador de archivos de Ckeditor.

28 May 2024, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-28 20:16

Updated : 2024-11-21 08:29


NVD link : CVE-2023-46694

Mitre link : CVE-2023-46694

CVE.ORG link : CVE-2023-46694


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type