Arbitrary File Upload Vulnerability in ThinkAdmin v6
CVE-2023-34833

6.1MEDIUM

Key Information:

Vendor

Thinkadmin

Vendor
CVE Published:
15 June 2023

What is CVE-2023-34833?

The vulnerability in ThinkAdmin v6's /api/upload.php component allows attackers to upload malicious files, potentially leading to the execution of arbitrary code. This flaw exposes systems to various attacks, making it crucial for users to implement immediate security measures to safeguard their applications.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.