Vulnerability Description
Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the server through the image upload functionality. This occurs because the application does not validate that the uploaded image is actually an image.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ulearn Project | Ulearn | - |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/scott/Third Party Advisory
- https://fluidattacks.com/advisories/scott/Third Party Advisory
- https://fluidattacks.com/advisories/scott/Third Party Advisory
FAQ
What is CVE-2023-0670?
CVE-2023-0670 is a vulnerability with a CVSS score of 7.2 (HIGH). Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the server through the image upload functionality. This occ...
How severe is CVE-2023-0670?
CVE-2023-0670 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0670?
Check the references section above for vendor advisories and patch information. Affected products include: Ulearn Project Ulearn.