CVE-2023-41266: Qlik Sense Enterprise – Path Traversal

CVE-2023-41266: Qlik Sense Enterprise - Path Traversal-渗透云记 - 专注于网络安全与技术分享
CVE-2023-41266: Qlik Sense Enterprise – Path Traversal
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-41266: Qlik Sense Enterprise – Path Traversal

漏洞描述

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享