Description
Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.
INFO
Published Date :
2024-05-28T19:21:18.374Z
Last Modified :
2025-02-13T15:46:56.032Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2023-46694 vulnerability.
| Vendors | Products |
|---|---|
| Vtenext |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2023-46694.
| URL | Resource |
|---|---|
| https://github.com/invisiblebyte/CVE-2023-46694 |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact