CVE-2023-48376: Csharp Cws Collaborative Development Platform
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Affected products
- Csharp Cws Collaborative Development Platform: version 10.25 only
Published 2023-12-15. Last modified 2026-06-17.