CVE-2023-52252
Published Dec 30, 2023Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
Vendor/product archive
2 CVEs tagged to unifiedremote / unified_remote — 2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable…