Description
A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash book entry. Afterwards, the attacker may visit the web shell and execute arbitrary commands.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pq98-6hf6-3rj3 | Economizzer remote code execution vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T17:54:39.229Z
Reserved: 2023-07-25T00:00:00.000Z
Link: CVE-2023-38874
No data.
Status : Modified
Published: 2023-09-28T04:15:12.223
Modified: 2024-11-21T08:14:20.360
Link: CVE-2023-38874
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA