HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-6973-45872-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-03-27 04:15
Updated : 2023-03-31 14:22
NVD link : CVE-2023-25909
Mitre link : CVE-2023-25909
CVE.ORG link : CVE-2023-25909
JSON object : View
Products Affected
hgiga
- oaklouds_portal
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type