CVE-2023-4480
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Sep 5, 2023
Updated: Sep 8, 2023
CWE ID 22
CWE ID 538
Summary
CVE-2023-4480 is a vulnerability affecting the "Fusion File Manager" component in certain systems. When accessed through the admin panel, an outdated dependency in this component allows attackers to read files with the privileges of the running process. They can also write files to arbitrary locations, subject to the application's mime-type and file extension validation. This issue stems from an outdated component and poses a significant risk for unauthorized file access and modification.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share