Unrated severityNVD Advisory· Published Aug 28, 2023· Updated Oct 3, 2024
Saho ADM100&ADM-100FP - Arbitrary File Upload
CVE-2023-38029
Description
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.