ZeroHour

CVE-2023-0265

PoC
CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
Modified
Description

Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.

Vendors
uvdesk
Products
community-skeleton
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.