← back
CVE-2023-6723

Unrestricted Upload of File with Dangerous Type in Repox

CVSS 10 CRITICALEPSS 0.8%CWE-434
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 10EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation controls, resulting in a full system compromise.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Repox · Repox

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →