H
CL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server.
References
| Link | Resource |
|---|---|
| https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
| https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:27
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.6 |
| References | () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109608 - Vendor Advisory |
Information
Published : 2024-01-03 03:15
Updated : 2025-06-18 16:15
NVD link : CVE-2023-45723
Mitre link : CVE-2023-45723
CVE.ORG link : CVE-2023-45723
JSON object : View
Products Affected
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')