CVE-2023-52252 Information
Dec 31, 2023
cve
Description
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
Reference
https://harkenzo.tlstickle.com/2023-03-17-UR-Web-Triggerable-RCE/ https://www.exploit-db.com/exploits/51309
Share on: