CVE-2023-6850
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-6850 is a critical vulnerability affecting the kalcaddle KodExplorer up to version 4.51.03. This issue lies in the component API Endpoint Handler's /index.php?pluginApp/to/yzOffice/getFile, where an unrestricted upload can be triggered by manipulating the argument path/file. The attack can be initiated remotely, and the exploit has been made public, increasing the risk. Upgrading to version 4.52.01, which includes the patch with the identifier 5cf233f7556b442100cf67b5e92d57ceabb126c6, is recommended as a mitigation measure. VDB-248218 is the identifier assigned to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Kodcloud Kodexplorer