Arbitrary File Upload Flaw in PerfreeBlog by Perfree
CVE-2023-27757
9.8CRITICAL
What is CVE-2023-27757?
An arbitrary file upload vulnerability exists in the /admin/user/uploadImg component of PerfreeBlog v3.1.1. This security weakness allows malicious attackers to upload crafted JPG files, which can lead to the execution of arbitrary code on the server. The flaw poses significant risks, potentially compromising the security of affected installations. Users are advised to review their systems and apply the necessary updates to mitigate the threat.
