CVE-2020-23043

HIGH

Tran Tu Air Sender v1.0.2 - Code Injection

Title source: llm
STIX 2.1

Description

Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.vulnerability-lab.com/get_content.php?id=2212

Scores

CVSS v3 8.8
EPSS 0.0093
EPSS Percentile 76.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
air_sender_project/air_sender 1.0.2
Published Oct 22, 2021
Tracked Since Feb 18, 2026