cve/2023/CVE-2023-38029.md
2024-05-25 21:48:12 +02:00

1012 B
Raw Blame History

CVE-2023-38029

Description

Sahos attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.

POC

Reference

No PoCs from references.

Github