A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
History

Fri, 03 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-03T19:28:07.534Z

Reserved: 2023-04-29T00:00:00

Link: CVE-2023-31541

cve-icon Vulnrichment

Updated: 2024-08-02T14:53:31.029Z

cve-icon NVD

Status : Modified

Published: 2023-06-13T17:15:14.810

Modified: 2025-01-03T20:15:26.650

Link: CVE-2023-31541

cve-icon Redhat

No data.