An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".
History

Fri, 31 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-31T16:39:27.153Z

Reserved: 2023-09-08T00:00:00.000Z

Link: CVE-2023-42248

cve-icon Vulnrichment

Updated: 2025-01-15T18:54:22.085Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-13T22:15:13.293

Modified: 2025-01-31T17:15:11.570

Link: CVE-2023-42248

cve-icon Redhat

No data.