Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform updatelib.php unrestricted upload
CVE-2023-5491
What is CVE-2023-5491?
A vulnerability exists in the Byzoro Smart S45F Multi-Service Secure Gateway's management platform, specifically within the file handling of /sysmanage/updatelib.php. This flaw allows for unrestricted file uploads through manipulation of the 'file_upload' argument, posing severe security risks as it may allow unauthorized users to upload malicious files remotely. This issue has been publicly disclosed, and the lack of vendor response raises concerns about the potential for exploitation.
Affected Version(s)
Smart S45F Multi-Service Secure Gateway Intelligent Management Platform 20230928
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved