Hidden Page Vulnerability Allows Execution of System Commands
CVE-2024-3123
7.2HIGH
What is CVE-2024-3123?
The vulnerability in CHANGING Mobile One Time Password arises from a flaw in its file uploading function located on a hidden page. This flaw allows remote attackers with administrative privileges to upload malicious files due to improper filtering of file types. Once uploaded, these files can be executed by the system, enabling attackers to run arbitrary system commands. This exposes the system to various risks, including unauthorized access and potential data breaches.
Affected Version(s)
Mobile One Time Password 3.11 <= 3.11.3
