CVE-2023-23607 is a critical unrestricted file upload vulnerability affecting erohtar/Dasherr, a dashboard for self-hosted services. This flaw, present in versions prior to 1.05.00, allows unauthenticated attackers to upload arbitrary files, including PHP scripts, to any location on the server. With a CVSS score of 9.8 (CRITICAL), successful exploitation grants complete compromise of confidentiality, integrity, and availability. While there are no known workarounds, users are strongly advised to upgrade to version 1.05.00 or later. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.05.00CPE matchmatch criteria | cpe:2.3:a:dasherr_project:dasherr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.