CVE-2023-31541: Malicious File Upload
Published Jun 13, 2023
·Updated
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
Affected Software
1 affected component
CKEditor Ckeditor Redmine=1.2.3
Event History
Jun 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-31541?
CVE-2023-31541 is an unrestricted file upload vulnerability in the 'Browse and upload images' feature of the CKEditor v1.2.3 plugin for Redmine.
2
How severe is CVE-2023-31541?
CVE-2023-31541 has a severity rating of 9.8, which is considered critical.
3
Which software is affected by CVE-2023-31541?
The CKEditor v1.2.3 plugin for Redmine is affected by CVE-2023-31541.
4
How can I fix CVE-2023-31541?
To fix CVE-2023-31541, you should update the CKEditor plugin for Redmine to a version that does not have this vulnerability.
5
What is the CWE of CVE-2023-31541?
CVE-2023-31541 falls under CWE-434, which is for Unrestricted Upload of File with Dangerous Type.