6.5

CVE-2023-7026

Exploit

Lightxun IPTV Gateway web_upload_template.html unrestricted upload

A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of the file /ZHGXTV/index.php/admin/index/web_upload_template.html. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248579.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LightxunIptv Gateway Version <= 20231208
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.454
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
cna@vuldb.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
cna@vuldb.com 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://github.com/willchen0011/cve/blob/main/upload2.md
Exploit
https://vuldb.com/?ctiid.248579
Permissions Required
https://vuldb.com/?id.248579
Third Party Advisory