The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges.
This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0 before 4.6.0.105, from 4.7.0.0 before 4.7.0.103.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ONEKEY
Published: 2023-02-16T09:07:09.930Z
Updated: 2024-08-02T05:24:34.659Z
Reserved: 2023-02-16T09:01:36.192Z
Link: CVE-2023-0862
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-02-16T10:15:11.983
Modified: 2024-11-21T07:37:59.533
Link: CVE-2023-0862
Redhat
No data.