Sept. 20, 2023, 2:57 p.m. | Emmaline

Blog - Praetorian www.praetorian.com

Overview On August 29th, 2023 Qlik issued a patch for two vulnerabilities we identified in Qlik Sense Enterprise, CVE-2023-41265 and CVE-2023-41266. These vulnerabilities allowed for unauthenticated remote code execution via path traversal and HTTP request tunneling. As part of our standard operating procedure, we performed a diff of the issued patch to identify potential bypasses […]


The post Advisory: Qlik Original Fix for CVE 2023-41265 Vulnerable to RCE appeared first on Praetorian.

advisory august code code execution cve enterprise fix http labs patch path path traversal procedure qlik qlik sense rce remote code remote code execution request standard tunneling unauthenticated vulnerabilities vulnerability research vulnerable

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC