Vulnerabilities > CVE-2023-43981 - Deserialization of Untrusted Data vulnerability in Presto-Changeo Test Site Creator 1.1.1

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
presto-changeo
CWE-502
critical

Summary

Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.

Vulnerable Configurations

Part Description Count
Application
Presto-Changeo
1

Common Weakness Enumeration (CWE)