Unrestricted Upload of File with Dangerous Type in fossbilling/fossbilling
CVE-2023-3491

8HIGH

Key Information:

Vendor
CVE Published:
30 June 2023

What is CVE-2023-3491?

FossBilling prior to version 0.5.3 has a vulnerability that allows unrestricted file uploads of dangerous file types. This flaw can potentially allow unauthorized users to upload malicious files, which could jeopardize the server's integrity and lead to further exploitation. It is crucial for users of FossBilling to upgrade to version 0.5.3 or later to mitigate this risk and enhance their security posture.

Affected Version(s)

fossbilling/fossbilling < 0.5.3

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.