CVE-2023-48031
- Reference to the description:
- Description:
- OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the attacker to execute arbitrary code or establish a reverse shell, leading to unauthorized file writes or control over the victim's station via a crafted file upload operation.
- Last updated date:
- 08/29/2024
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 11/25/2023
- Reference url to background