{ "id": "CVE-2023-28128", "sourceIdentifier": "support@hackerone.com", "published": "2023-05-09T22:15:09.920", "lastModified": "2023-05-09T22:15:09.920", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution." } ], "metrics": {}, "weaknesses": [ { "source": "support@hackerone.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-434" } ] } ], "references": [ { "url": "https://forums.ivanti.com/s/article/ZDI-CAN-17812-Ivanti-Avalanche-FileStoreConfig-Arbitrary-File-Upload-Remote-Code-Execution-Vulnerability?language=en_US", "source": "support@hackerone.com" } ] }