It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. This issue affects Document On-line Submission and Approval System: 22547, 22567.
History

Thu, 24 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-07-20T02:45:25.479Z

Updated: 2024-10-24T18:46:57.664Z

Reserved: 2023-06-30T02:08:23.931Z

Link: CVE-2023-37289

cve-icon Vulnrichment

Updated: 2024-08-02T17:09:34.180Z

cve-icon NVD

Status : Modified

Published: 2023-07-20T03:15:10.047

Modified: 2024-11-21T08:11:24.457

Link: CVE-2023-37289

cve-icon Redhat

No data.