An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
https://github.com/rootd4ddy/CVE-2023-43838
https://github.com/rootd4ddy/
https://github.com/Volmarg/personal-management-system/blob/39d3c0df641a5435f2028b37a27d26ba61a3b97b/src/assets/scripts/core/ui/DataProcessor/SpecialAction.ts#L35
https://github.com/Volmarg/personal-management-system
https://github.com/Volmarg
http://www.w3.org/2000/svg
Source: Mitre, NVD
Published: 2023-10-04
Updated: 2023-10-06
Base Score: 7.2
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H