Unrated severityNVD Advisory· Published Dec 15, 2023· Updated Aug 2, 2024
Kaifa Technology WebITR - Arbitrary File Upload
CVE-2023-48394
Description
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Affected products
1- Range: 2_1_0_19
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.