File Upload Flaw in Antabot White-Jotter Software
CVE-2023-29635

9.8CRITICAL

What is CVE-2023-29635?

A vulnerability exists in Antabot's White-Jotter software version 0.2.2, allowing remote attackers to exploit the file upload functionality. Specifically, the flaw is found in the coversUpload function, where insufficient validation of uploaded files permits execution of arbitrary code. This risk underlines the necessity for stringent input validation and effective security measures to protect against such attacks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-29635 : File Upload Flaw in Antabot White-Jotter Software