go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

SmartStar Software CWS Web-Base - Arbitrary File Upload

TVN ID TVN-202312006
CVE ID CVE-2023-48376
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products SmartStar Software CWS Web-Base v10.25
Description SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Solution Update to the latest version.
Credit Kun Xian Lin(DEVCORE)
Public Date 2023-12-15
Top