High severity8.8NVD Advisory· Published Jun 2, 2023· Updated Jun 17, 2026
CVE-2023-28699
CVE-2023-28699
Description
Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload a PHP file containing a webshell to perform arbitrary system operation or disrupt service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WADE DIGITAL DESIGN CO, LTD./FANTSYv5Range: 2.1.8
Patches
Vulnerability mechanics
References
1- www.twcert.org.tw/tw/cp-132-7102-41ab8-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.