Back to Database
Status published
High
CVE-2024-3123
CHANGING Mobile One Time Password - Arbitrary File Upload
Vulnerability Description
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3123
Credits & Attribution
No credits recorded in the NVD database.
References
More from CHANGING
View All →CVE-2024-3122
CHANGING Mobile One Time Password - Arbitrary File Reading
Medium
4.9
CVE-2020-3939
SysJust Syuan-Gu-Da-Shih -Cross-Site Scripting(XSS)
Medium
6.1
CVE-2020-3938
SysJust Syuan-Gu-Da-Shih -Request-Forgery
Critical
9.8
CVE-2020-3937
SysJust Syuan-Gu-Da-Shih-SQL injection
High
8.1
CVE-2020-3927
ServiSign Windows Versions- Arbitrary File Deletion
High
8.3
Affected Vendor
CHANGING
View all reports →Affected Software
Mobile One Time Password
Vulnerable Versions:
3.11
Timeline
Official Publish:
July 1st, 2024
Last Modified:
August 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H