Vulnerability record · CVE-2023-22855 · published 15 February 2023
CVE-2023-22855: Kardex control center code injection vulnerability
Kardex · Kardex Control Center
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote files on SMB shares. If one provides a file with the extension .t4, it is rendered with the .NET templating engine mono/t4, which can execute code.
Description
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote files on SMB shares. If one provides a file with the extension .t4, it is rendered with the .NET templating engine mono/t4, which can execute code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/171046/Kardex-Mlog-MCC-5.7.12-0-a203c2a213-master-File-Inclusion-Remote-Code-Execut | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/171689/Kardex-Mlog-MCC-5.7.12-Remote-Code-Execution.html | |
| http://seclists.org/fulldisclosure/2023/Feb/10 | ExploitMailing ListThird Party Advisory |
| https://github.com/patrickhener/CVE-2023-22855/blob/main/advisory/advisory.md | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/51239 | |
| http://packetstormsecurity.com/files/171046/Kardex-Mlog-MCC-5.7.12-0-a203c2a213-master-File-Inclusion-Remote-Code-Execut | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/171689/Kardex-Mlog-MCC-5.7.12-Remote-Code-Execution.html | |
| http://seclists.org/fulldisclosure/2023/Feb/10 | ExploitMailing ListThird Party Advisory |
| https://github.com/patrickhener/CVE-2023-22855/blob/main/advisory/advisory.md | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/51239 |
Track CVE-2023-22855 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-22855), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.