gitee.comexploit
https://gitee.com/wkstestete/cve/blob/master/upload/upload1.md CVE-2023-1797
MEDIUM
OTCMS unrestricted upload
Record summary
CVE-2023-1797 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.php?mudi=sql. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224749 was assigned to this vulnerability.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OTCMS | CVE List | 6.0.1 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-1797 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.224749 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.224749