VYPR
Unrated severityNVD Advisory· Published Jun 2, 2023· Updated Jan 8, 2025

ITPison OMICARD EDM - Arbitrary File Upload

CVE-2023-28700

Description

OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with administrator privileges can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.