CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T19:32:42.884Z

Reserved: 2024-04-01T03:08:28.782Z

Link: CVE-2024-3123

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.884Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-01T05:15:04.973

Modified: 2024-11-21T09:28:57.103

Link: CVE-2024-3123

cve-icon Redhat

No data.