In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2023-04-17T07:32:24.262Z

Updated: 2024-08-02T05:32:46.389Z

Reserved: 2023-03-01T05:58:56.947Z

Link: CVE-2023-1109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-17T08:15:07.627

Modified: 2023-04-26T23:00:01.937

Link: CVE-2023-1109

cve-icon Redhat

No data.