Vulnerability Details CVE-2023-31541
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.055
EPSS Ranking 90.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-31541
-
cpe:2.3:a:ckeditor:ckeditor:1.2.3