Description
In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33308 | In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T14:14:39.826Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-29770
No data.
Status : Modified
Published: 2023-11-28T00:15:07.033
Modified: 2024-11-21T07:57:30.110
Link: CVE-2023-29770
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD