An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
References
Link | Resource |
---|---|
http://www.w3.org/2000/svg | Not Applicable |
https://github.com/Volmarg | Not Applicable |
https://github.com/Volmarg/personal-management-system | Product |
https://github.com/Volmarg/personal-management-system/blob/39d3c0df641a5435f2028b37a27d26ba61a3b97b/src/assets/scripts/core/ui/DataProcessor/SpecialAction.ts#L35 | Vendor Advisory |
https://github.com/rootd4ddy/ | Not Applicable |
https://github.com/rootd4ddy/CVE-2023-43838 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-10-04 16:15
Updated : 2023-10-06 16:14
NVD link : CVE-2023-43838
Mitre link : CVE-2023-43838
CVE.ORG link : CVE-2023-43838
JSON object : View
Products Affected
personal-management-system
- personal_management_system
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type