← back
CVE-2023-4409

NBS&HappySoftWeChat unrestricted upload

CVSS 6.3 MEDIUMEPSS 0.8%CWE-434
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
18 Aug 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237512.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L