CVE-2023-1970 is an unrestricted file upload vulnerability affecting yuan1994 tpAdmin 1.3.12, specifically within the Upload function of application\admin\controller\Upload.php. This allows authenticated attackers to upload arbitrary files, potentially leading to full system compromise. The vulnerability has a CVSS score of 7.2 (High) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While publicly disclosed, there is no evidence of active exploitation, and exploit tools like Metasploit or Nuclei modules are unavailable. Community discussion and media coverage for this vulnerability are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.12CPE matchmatch criteria | cpe:2.3:a:tpadmin_project:tpadmin:1.3.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.