A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/controller.ashx?action=catchimage. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227230 is the identifier assigned to this vulnerability.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/MorStardust/hansuncmswebshell/blob/main/README.md | Exploit Third Party Advisory | 
| https://vuldb.com/?ctiid.227230 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.227230 | Third Party Advisory | 
| https://github.com/MorStardust/hansuncmswebshell/blob/main/README.md | Exploit Third Party Advisory | 
| https://vuldb.com/?ctiid.227230 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.227230 | Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 07:58
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 6.5
         v3 : 6.3  | 
| References | () https://github.com/MorStardust/hansuncmswebshell/blob/main/README.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.227230 - Permissions Required, Third Party Advisory | |
| References | () https://vuldb.com/?id.227230 - Third Party Advisory | 
02 May 2023, 17:41
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://vuldb.com/?ctiid.227230 - Permissions Required, Third Party Advisory | |
| References | (MISC) https://github.com/MorStardust/hansuncmswebshell/blob/main/README.md - Exploit, Third Party Advisory | |
| References | (MISC) https://vuldb.com/?id.227230 - Third Party Advisory | |
| CPE | cpe:2.3:a:hansuncms_project:hansuncms:1.4.3:*:*:*:*:*:*:* | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 9.8  | 
22 Apr 2023, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-04-22 17:15
Updated : 2025-02-04 17:15
NVD link : CVE-2023-2245
Mitre link : CVE-2023-2245
CVE.ORG link : CVE-2023-2245
JSON object : View
Products Affected
                hansuncms_project
- hansuncms
 
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
