CVE-2023-0670

HIGH

Ulearn - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the server through the image upload functionality. This occurs because the application does not validate that the uploaded image is actually an image.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0179
EPSS Percentile 82.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
ulearn_project/ulearn
Published Apr 05, 2023
Tracked Since Feb 18, 2026