Lucene search

K
cvelistFluid AttacksCVELIST:CVE-2023-0265
HistoryApr 04, 2023 - 12:00 a.m.

CVE-2023-0265

2023-04-0400:00:00
Fluid Attacks
www.cve.org
uvdesk
version 1.1.1
authenticated
remote
command execution
validation
profile pictures
customers

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.5%

Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Uvdesk",
    "versions": [
      {
        "version": "1.1.1",
        "status": "affected"
      }
    ]
  }
]

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.5%

Related for CVELIST:CVE-2023-0265