CVE-2023-23328: Avantfax

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file.

Affected products

Published 2023-03-10. Last modified 2026-07-09.