CVE Published: 25/07/2023 |
CVE Updated: 23/10/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: Generic Model Organism Database Project |
Product: GBrowse Status : PUBLISHED
CVE-2023-32637 Description
GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.