Vulnerability Details CVE-2023-26949
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-26949
-
cpe:2.3:a:onekeyadmin:onekeyadmin:1.3.9