CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-31724 CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Fixes

Solution

Update to MOTP 3.11.3 Patch 1 or later version or install the patch.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T19:32:42.884Z

Reserved: 2024-04-01T03:08:28.782Z

Link: CVE-2024-3123

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.884Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-01T05:15:04.973

Modified: 2024-11-21T09:28:57.103

Link: CVE-2024-3123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses