Arbitrary File Upload Vulnerability Allows Remote Attackers to Execute Arbitrary Code and Obtain Sensitive Information
CVE-2023-31505
7.2HIGH
Key Information:
- Vendor
Schlix CMS
- Status
- Vendor
- CVE Published:
- 31 January 2024
Badges
๐ฐ Ransomware๐พ Exploit Exists
What is CVE-2023-31505?
An arbitrary file upload vulnerability exists in Schlix CMS v2.2.8-1, which enables remote authenticated attackers to upload malicious .phtml files. This capability allows attackers to execute arbitrary code on the server and access sensitive data, creating an exploit vector that can lead to severe breaches of data integrity and confidentiality. Proper validation and sanitization of uploaded files are critical to prevent such vulnerabilities.
