CVE-2023-33253
Summary
| CVE | CVE-2023-33253 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-12 13:15:00 UTC |
| Updated | 2023-07-21 19:20:00 UTC |
| Description | LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Agilebio | Labcollector | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - Toxich4/CVE-2023-33253 | MISC | github.com | |
| All-in-One Lab Management & Notebook | LabCollector LIMS | MISC | labcollector.com | |
| Latest News About LabCollector | LabCollecor LIMS | MISC | labcollector.com | Release Notes |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.