← Back to browse · API

CVE-2023-3836

Severity
MEDIUM
CVSS
6.3
EPSS
0.7367
Risk score
50.98
CISA KEV
No
PoC
No
Published
2023-07-22
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-44464, GHSA-V896-JP39-6PQH
Products
Dahua:Smart Park Management 20230713
Sources
euvd EUVD-2023-44464

Description

A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References