An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted file to execute arbitrary code.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.telindus.lu/fr/produits/apsal | product |
https://excellium-services.com/cert-xlm-advisory/CVE-2023-26098 | third party advisory |
https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-26098 |