LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.
History

Sat, 04 Jan 2025 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-06-12T00:00:00

Updated: 2025-01-03T23:44:06.248Z

Reserved: 2023-05-21T00:00:00

Link: CVE-2023-33253

cve-icon Vulnrichment

Updated: 2024-08-02T15:39:36.234Z

cve-icon NVD

Status : Modified

Published: 2023-06-12T13:15:10.187

Modified: 2024-11-21T08:05:16.260

Link: CVE-2023-33253

cve-icon Redhat

No data.