CVE-2023-27168
קריטית 9.8
תיאור (מקור, אנגלית)
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-17/9/2026
- CWE
- CWE-434
מוצרים מושפעים
xpand-it: write-back manager
קישורים
- https://balwurk.github.io/CVE-2023-27168/ ExploitThird Party Advisory
- https://balwurk.github.io/CVE-2023-27168/ ExploitThird Party Advisory
- https://balwurk.com Not Applicable
- https://ghostline.neocities.org/CVE-2023-27168/
- https://writeback4t.com Not Applicable
- https://www.xpand-it.com Product
- https://balwurk.com Not Applicable
- https://writeback4t.com Not Applicable
- https://www.xpand-it.com Product