CVE-2023-28700
EUVD-2023-3234302.06.2023, 11:15
OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with administrator privileges can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| itpison | omicard_edm | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration