D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability
CVE-2023-32166
8.1HIGH
Summary
A directory traversal vulnerability exists in the D-Link D-View, specifically within the uploadFile function. This flaw arises from insufficient validation of user-supplied paths before they are utilized in file operations. As a result, an attacker with valid authentication can manipulate the system to create arbitrary files, potentially leading to unauthorized access or further exploitation within the affected installations. This risk highlights the critical need for proper input validation mechanisms to avert such security threats.
Affected Version(s)
D-View DLink D-View8 1.0.2.13
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved