Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP archive.
References
Link Resource
https://zuso.ai/Advisory/ZA-2023-04 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: ZUSO ART

Published: 2023-10-17T03:35:35.535Z

Updated: 2023-10-17T03:35:35.535Z

Reserved: 2023-05-30T09:41:32.477Z


Link: CVE-2023-34207

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-17T04:15:11.937

Modified: 2023-10-20T18:09:10.790


Link: CVE-2023-34207

JSON object: View

cve-icon Redhat Information

No data.

CWE