A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273273 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Aug 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:baidu:ueditor:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2024-08-01T04:31:04.276Z
Updated: 2024-08-01T13:28:02.073Z
Reserved: 2024-07-31T15:13:54.501Z
Link: CVE-2024-7342
Vulnrichment
Updated: 2024-08-01T13:27:58.528Z
NVD
Status : Analyzed
Published: 2024-08-01T05:15:10.303
Modified: 2024-08-15T18:40:22.537
Link: CVE-2024-7342
Redhat
No data.