CVE-2023-3796 is a high-severity unrestricted file upload vulnerability affecting Bug Finder Foody Friend version 1.0, specifically within the profile picture handling functionality. An authenticated attacker can remotely exploit this by manipulating the 'profile_picture' argument, leading to potential compromise of confidentiality, integrity, and availability. While the CVSS score is 8.8 (High), there is currently no public exploit code, Metasploit modules, or significant community discussion, and it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:bugfinder:foody_friend:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.