Vulnerabilities > Unifiedremote > Unified Remote > 3.13.0

DATE CVE VULNERABILITY TITLE RISK
2023-12-30 CVE-2023-52252 XXE vulnerability in Unifiedremote Unified Remote 3.13.0
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
network
low complexity
unifiedremote CWE-611
critical
9.8