VYPR
Unrated severityNVD Advisory· Published Dec 15, 2023· Updated Aug 2, 2024

Kaifa Technology WebITR - Arbitrary File Upload

CVE-2023-48394

Description

Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.