CVE-2023-41564
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
- Affected products
- Cockpit Cms
- Agentejo Cockpit
- = 2.6.3
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.0% (59th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2023-09-08
CVE-2023-41564 at NVD
2 known exploits for CVE-2023-41564
Proof-of-concept code and exploit modules indexed by Sploitus