Critical severity9.8NVD Advisory· Published Dec 30, 2023· Updated Jun 17, 2026
CVE-2023-52252
CVE-2023-52252
Description
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:unifiedremote:unified_remote:3.13.0:*:*:*:*:*:*:*
- Unified Remote/Unified Remotedescription
- Range: = 3.13.0
Patches
Vulnerability mechanics
References
2- harkenzo.tlstickle.com/2023-03-17-UR-Web-Triggerable-RCE/nvdExploit
- www.exploit-db.com/exploits/51309nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.