CVE-2023-1721Unrestricted File Upload in Class Registration System

Severity
7.2HIGHNVD
CNA9.1
EPSS
0.1%
top 73.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateAug 23

Description

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-fm2j-6967-6fqw: Yoga Class Registration System version 12023-06-24
CVEList
Yoga Class Registration System 1.0 - RCE2023-06-23

🕵️Threat Intelligence

2
Talos
Three vulnerabilities in NVIDIA graphics driver could cause memory corruption2023-08-23
Talos
Three vulnerabilities in NVIDIA graphics driver could cause memory corruption2023-08-23
CVE-2023-1721 — Unrestricted File Upload | cvebase