Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2023-29386
9.1CRITICAL
Summary
The vulnerability in Icomoon Manager allows for unrestricted file uploads, permitting attackers to upload malicious files that can compromise the security of the web application. This flaw affects versions from earlier releases to 2.0. By exploiting this vulnerability, an attacker may plant web shells or other payloads, which could lead to further unauthorized access or control over the affected systems. It is crucial for users of Icomoon Manager to implement security measures to mitigate the risks associated with this issue.
Affected Version(s)
Manager for Icomoon <= 2.0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
deokhunKim (Patchstack Alliance)