CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31724 | CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands. |
Fixes
Solution
Update to MOTP 3.11.3 Patch 1 or later version or install the patch.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T19:32:42.884Z
Reserved: 2024-04-01T03:08:28.782Z
Link: CVE-2024-3123
Updated: 2024-08-01T19:32:42.884Z
Status : Awaiting Analysis
Published: 2024-07-01T05:15:04.973
Modified: 2024-11-21T09:28:57.103
Link: CVE-2024-3123
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD