go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Kaifa Technology WebITR - Arbitrary File Upload

TVN ID TVN-202312021
CVE ID CVE-2023-48394
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products WebITR 2_1_0_23
Description Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Solution Update to the latest version
Credit Cyku(DEVCORE)
Public Date 2023-12-15
Top