Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.
References
Link | Resource |
---|---|
https://0xhunter20.medium.com/how-i-found-unrestricted-file-upload-in-fl3xx-ios-app-cve-2023-42335-6b1a72da6d65 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-09-20T00:00:00
Updated: 2023-09-20T19:35:35.200775
Reserved: 2023-09-08T00:00:00
Link: CVE-2023-42335
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-09-20T20:15:11.967
Modified: 2023-09-22T02:11:00.637
Link: CVE-2023-42335
JSON object: View
Redhat Information
No data.
CWE