File Upload Vulnerability in DWSurvey Software by DWSurvey
CVE-2023-40980
9.8CRITICAL
What is CVE-2023-40980?
A security weakness has been identified in DWSurvey-OSS versions up to 3.2.0, enabling remote attackers to exploit a file upload functionality. The flaw resides in the saveimage method and the savveFile function within the action/UploadAction.java file. This vulnerability could allow attackers to execute arbitrary code, posing significant risks to the integrity and confidentiality of the system.
