CVE-2023-5790
published 2023-10-26CVE-2023-5790: A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.78%
51.7th percentile
A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-file.php. The manipulation of the argument uploadedFileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243595.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_edge | — | — |
| msrc | microsoft_edge_extended_stable | — | — |
| remyandrade | file_manager_app | — | — |
| sourcecodester | file_manager_app | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j3jp-4g73-9xxh: A vulnerability classified as critical was found in SourceCodester File Manager App 1
ghsa_unreviewed·2023-10-26
CVE-2023-5790 [MEDIUM] CWE-434 GHSA-j3jp-4g73-9xxh: A vulnerability classified as critical was found in SourceCodester File Manager App 1
A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-file.php. The manipulation of the argument uploadedFileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243595.
Microsoft
Chromium: CVE-2023-3728 Use after free in WebRTC
vendor_msrc·2023-07-11·CVSS 8.8
CVE-2023-3728 [HIGH] Chromium: CVE-2023-3728 Use after free in WebRTC
Chromium: CVE-2023-3728 Use after free in WebRTC
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge
Microsoft
Chromium: CVE-2023-3730 Use after free in Tab Groups
vendor_msrc·2023-07-11·CVSS 8.8
CVE-2023-3730 [HIGH] Chromium: CVE-2023-3730 Use after free in Tab Groups
Chromium: CVE-2023-3730 Use after free in Tab Groups
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft
Microsoft
Chromium: CVE-2023-3727 Use after free in WebRTC
vendor_msrc·2023-07-11·CVSS 8.8
CVE-2023-3727 [HIGH] Chromium: CVE-2023-3727 Use after free in WebRTC
Chromium: CVE-2023-3727 Use after free in WebRTC
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge
Microsoft
Chromium: CVE-2023-3740 Insufficient validation of untrusted input in Themes
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-3740 [MEDIUM] Chromium: CVE-2023-3740 Insufficient validation of untrusted input in Themes
Chromium: CVE-2023-3740 Insufficient validation of untrusted input in Themes
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the late
Microsoft
Chromium: CVE-2023-3737 Inappropriate implementation in Notifications
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-3737 [MEDIUM] Chromium: CVE-2023-3737 Inappropriate implementation in Notifications
Chromium: CVE-2023-3737 Inappropriate implementation in Notifications
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest vers
Microsoft
Chromium: CVE-2023-3738 Inappropriate implementation in Autofill
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-3738 [MEDIUM] Chromium: CVE-2023-3738 Inappropriate implementation in Autofill
Chromium: CVE-2023-3738 Inappropriate implementation in Autofill
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version o
Microsoft
Chromium: CVE-2023-3736 Inappropriate implementation in Custom Tabs
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-3736 [MEDIUM] Chromium: CVE-2023-3736 Inappropriate implementation in Custom Tabs
Chromium: CVE-2023-3736 Inappropriate implementation in Custom Tabs
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest versio
Microsoft
Chromium: CVE-2023-3735 Inappropriate implementation in Web API Permission Prompts
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-3735 [MEDIUM] Chromium: CVE-2023-3735 Inappropriate implementation in Web API Permission Prompts
Chromium: CVE-2023-3735 Inappropriate implementation in Web API Permission Prompts
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that th
Microsoft
Chromium: CVE-2023-3732 Out of bounds memory access in Mojo
vendor_msrc·2023-07-11·CVSS 8.8
CVE-2023-3732 [HIGH] Chromium: CVE-2023-3732 Out of bounds memory access in Mojo
Chromium: CVE-2023-3732 Out of bounds memory access in Mojo
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Mic
Microsoft
Chromium: CVE-2023-3734 Inappropriate implementation in Picture In Picture
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-3734 [MEDIUM] Chromium: CVE-2023-3734 Inappropriate implementation in Picture In Picture
Chromium: CVE-2023-3734 Inappropriate implementation in Picture In Picture
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest
Microsoft
Chromium: CVE-2023-3733 Inappropriate implementation in WebApp Installs
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-3733 [MEDIUM] Chromium: CVE-2023-3733 Inappropriate implementation in WebApp Installs
Chromium: CVE-2023-3733 Inappropriate implementation in WebApp Installs
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest ve
Microsoft
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
vendor_msrc·2023-07-11·CVSS 6.5
CVE-2023-38187 [MEDIUM] Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
115.0.1901.183
115.0.5790.98/99
7/21/2023
Extended Stable
114.0.1901.183
114.0.5735.243
7/21/2023
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify li
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Yp1oneer/cve_hub/blob/main/File%20Manager%20App/Unrestricted%20File%20Upload.pdfhttps://vuldb.com/?ctiid.243595https://vuldb.com/?id.243595https://github.com/Yp1oneer/cve_hub/blob/main/File%20Manager%20App/Unrestricted%20File%20Upload.pdfhttps://vuldb.com/?ctiid.243595https://vuldb.com/?id.243595
2023-10-26
Published