CVE-2023-34833

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jun 15, 2023
Updated: Dec 7, 2023
CWE ID 434

Summary

CVE-2023-34833 is a critical vulnerability affecting the /api/upload.php component in ThinkAdmin v6. This issue permits attackers to upload arbitrary files, which could result in the execution of malicious code on the targeted system. Successful exploitation of this vulnerability could lead to serious security consequences, including data theft, unauthorized system access, or even system takeover. Attackers can exploit this vulnerability by crafting a specially designed file to upload, bypassing the intended file type restrictions. Organizations using ThinkAdmin v6 are encouraged to apply the available patch or upgrade to a newer, secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share