vendor:
Rukovoditel
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
Remote Code Execution (RCE)
CWE
Product Name: Rukovoditel
Affected Version From: 3.3.2001
Affected Version To: 3.3.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
Rukovoditel 3.3.1 – Remote Code Execution (RCE)
The vulnerability allows remote attackers to execute arbitrary code on the affected system by injecting PHP code into the metadata of a JPEG file and uploading it as a profile photo.
Mitigation:
Update to the latest version of Rukovoditel