Skip to content
COOEY

EXPOSURES › CVE-2023-31541

CVE-2023-31541

CRITICAL
DETAIL
SourceNVD · cve Published2023-06-13 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-31541 ↗
⚡ RCE SHAME 50/100 rce

A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.