CVE-2023-52252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
30/12/2023
Last modified:
05/01/2024

Description

Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unifiedremote:unified_remote:3.13.0:*:*:*:*:*:*:*