CVE-2024-3123

CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Configurations

No configuration.

History

No history.

Information

Published : 2024-07-01 05:15

Updated : 2024-07-01 12:37


NVD link : CVE-2024-3123

Mitre link : CVE-2024-3123

CVE.ORG link : CVE-2024-3123


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type