CVE detail
CVE-2023-48031 — CVE-2023-48031
Published 2023-11-17 · Modified 2026-06-17 · Vendor opensupports · Product opensupports · Source nvd
CRITICAL
severity
CVSS-derived band
0.0144
EPSS probability
exploitation probability, 30d
71.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the attacker to execute arbitrary code or establish a reverse shell, leading to unauthorized file writes or control over the victim's station via a crafted file upload operation.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References