Arbitrary File Upload Vulnerability in Jaspersoft Clarity PPM
CVE-2023-37790
5.4MEDIUM
What is CVE-2023-37790?
Jaspersoft Clarity PPM version 14.3.0.298 is vulnerable to an arbitrary file upload due to insufficient validation of user-uploaded files through the Profile Picture Upload feature. This security flaw could allow unauthorized users to upload malicious files, potentially compromising the integrity of the system and allowing for further attacks.