CVE-2023-48248

The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2024-01-10 11:15

Updated : 2024-01-10 13:56


NVD link : CVE-2023-48248

Mitre link : CVE-2023-48248


JSON object : View

Products Affected

No product.

CWE

No CWE.