A vulnerability classified as critical has been found in Stud.IP up to 5.0.8/5.1.6/5.2.5/5.3.3. Affected is the function
upload_action/edit_action
. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2023-50982. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.