CVE Published: 23/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: MicroEngine Inc. |
Product: MicroEngine Mailform Status : PUBLISHED
CVE-2023-27397 Description
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product\'s file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.