CNVD-2023-96945 Scanner

Our scanner targets the arbitrary file upload vulnerability in the McVie Safety Digital Management Platform. This vulnerability allows attackers to upload malicious files, potentially gaining unauthorized server access.


CNVD-2023-96945 Scanner Detail

Vulnerability Overview

The McVie Safety Digital Management Platform is found to have a file upload vulnerability that could be exploited by attackers to upload malicious files and potentially gain server permissions.

Vulnerability Details

This vulnerability stems from insufficient validation of uploaded files on the /Content/Plugins/uploader/FileChoose.html endpoint. Attackers can exploit this to upload executable files, leading to unauthorized access or server compromise.

Possible Effects

  • Unauthorized server access
  • Execution of arbitrary code
  • Disclosure of sensitive information

