MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.
References
Link | Resource |
---|---|
https://github.com/b1ackc4t/MarsCTF/blob/V1.2.1/src/main/java/com/b1ackc4t/marsctfserver/service/impl/CTFFileServiceImpl.java#L46 | Product |
https://github.com/b1ackc4t/MarsCTF/issues/10 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-06-05 15:15
Updated : 2023-06-09 22:42
NVD link : CVE-2023-33386
Mitre link : CVE-2023-33386
CVE.ORG link : CVE-2023-33386
JSON object : View
Products Affected
marsctf_project
- marsctf
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type