Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-84328
HistoryOct 20, 2023 - 12:00 a.m.

HCL Technologies Compass File Upload Vulnerability

2023-10-2000:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
hcl technologies compass
file upload
vulnerability
validation
uploaded files
arbitrary code
php code
security issue

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

HCL Technologies Compass is a low-code change management software from HCL Technologies, USA. Manages the full range of testing activities and integration with developer tools. HCL Technologies Compass suffers from a file upload vulnerability that stems from the application’s lack of effective validation of uploaded files. An attacker can exploit this vulnerability to upload a malicious script that executes arbitrary PHP code on the system.

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

Related for CNVD-2023-84328