Filtered by vendor Wddgroup
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-28699 | 1 Wddgroup | 1 Fantasy | 2023-06-09 | N/A | 8.8 HIGH |
Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload a PHP file containing a webshell to perform arbitrary system operation or disrupt service. | |||||
CVE-2023-28698 | 1 Wddgroup | 1 Fantsy | 2023-06-09 | N/A | 9.8 CRITICAL |
Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by modifying URL parameters to gain administrator privileges to perform arbitrary system operation or disrupt service. |