CVE-2023-48031
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 17, 2023
Updated: Nov 25, 2023
CWE ID 434
Summary
CVE-2023-48031 is a vulnerability affecting OpenSupports v4.11.0. In this version, the comment function contains an unrestricted file upload flaw. An attacker can exploit this by manipulating the file's magic bytes, making a .bat file appear as an allowed type. This enables the attacker to execute arbitrary code or establish a reverse shell, potentially leading to unauthorized file writes or control over the victim's station. This vulnerability can be exploited through a crafted file upload operation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.