vendor:
Boss Mini
by:
nltt0
8.1
CVSS
CRITICAL
Local File Inclusion
22
CWE
Product Name: Boss Mini
Affected Version From: 1.4.2000
Affected Version To: 1.4.2000
Patch Exists: NO
Related CWE: CVE-2023-3643
CPE: a:boss_mini:boss_mini:1.4.0
Platforms Tested:
2023
Boss Mini 1.4.0 – Local File Inclusion
The Boss Mini version 1.4.0 is vulnerable to local file inclusion due to improper input validation. An attacker can exploit this vulnerability to read arbitrary files on the system. This exploit has been assigned CVE-2023-3643.
Mitigation:
To mitigate this vulnerability, ensure proper input validation is implemented to prevent malicious file inclusions. Regularly update the software to the latest version to patch known security issues.