CVE-2023-32637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
25/07/2023
Last modified:
02/08/2024

Description

GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gmod:gbrowse:-:*:*:*:*:*:*:*