Back

CRITICAL

HGiga Inc. OAKlouds - Arbitrary File Upload

Published Mar 27, 2023

Description

HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.

Affected products

Remediation

Vendor solution

- Update OAKlouds-layout-2.0 to OAKlouds-layout-2.0-10 - Update OAKlouds-layout-3.0 to OAKlouds-layout-3.0-10

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner twcert
Published Mar 27, 2023
Updated Feb 19, 2025
Reserved Feb 16, 2023

CISA Vulnrichment

Updated Feb 19, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner twcert
Published Mar 27, 2023
Updated Feb 19, 2025

GitHub

No data