8.8

CVE-2023-36348

Exploit
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codekop ≫ Codekop Version 2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.37% 0.928
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://yuyudhn.github.io/pos-codekop-vulnerability/
Third Party Advisory
Exploit
http://packetstormsecurity.com/files/173278/POS-Codekop-2.0-Shell-Upload.html
https://www.youtube.com/watch?v=Ge0zqY0sGiQ
Third Party Advisory
Exploit