Vulnerabilities > CVE-2023-28700 - Unspecified vulnerability in Itpison Omicard EDM
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with administrator privileges can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |