Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-46694 PoC — Vtenext 安全漏洞

Source
Associated Vulnerability
Title:Vtenext 安全漏洞 (CVE-2023-46694)
Description:Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.
Description
CVE-2023-46694 proof-of-concept
Readme
# CVE-2023-46694

**Discovered by: Federico Zambito with Innovery**

## Summary

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, resulting in remote code execution. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

Discovery date: 11/04/23

05/07/23 - Vendor contacted by email (1st time)

11/07/23 - Report sent to the vendor

25/10/23 - CVE issued CVE-2023-46694

17/11/23 - Vendor contacted again but no response

01/03/24 - Public disclosure
File Snapshot

[4.0K] /data/pocs/ba1b3df8ff10f5b465b7526cd9dee1455ce7c37d ├── [4.0K] CVE-2023-46694 │   ├── [5.5K] CVE-2023-46694.py │   └── [ 92] earth_sh.jpg └── [ 571] README.md 1 directory, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →