← Back to CVE List

CVE-2023-48248

Published: 2024-01-10T11:15Z
Last Modified: 2024-11-21T08:31Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt