CVE-2023-26578

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
25/10/2023
Last modified:
28/10/2023

Description

Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:idattend:idweb:3.1.013:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools