Description

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

INFO

Published Date :

2024-05-28T19:21:18.374Z

Last Modified :

2025-02-13T15:46:56.032Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2023-46694 vulnerability.

Vendors Products
Vtenext
  • Vtenext
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2023-46694.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact