packetstormsecurity.com
http://packetstormsecurity.com/files/171705/Monitorr-1.7.6-Cross-Site-Scripting.html CVE-2023-26775
HIGH
monitorr monitorr Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2023-26775 has a selected CVSS score of 7.8 (high).
Description
File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 10, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
monitorrBrowse monitorr / monitorr | VulnCheck | Version data not supplied | |
References
6github.com
https://github.com/Monitorr github.com
https://github.com/Monitorr/Monitorr github.com
https://github.com/Monitorr/Monitorr/blob/3ebfd915bfb02aae2ded08c5e4ba6b1bea3009f2/assets/php/upload.php nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-26775 twitter.com
https://twitter.com/retrymp3