PT-2014-5332 · Drupal · Flag

Murray Mcallister

·

Publicado

2014-05-17

·

Atualizado

2014-05-19

·

CVE-2014-3453

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Flag module versions 7.x-3.0 through 7.x-3.5
Description The issue allows remote authenticated administrators to execute arbitrary PHP code via the "Flag import code" text area in the /admin/structure/flags/import API endpoint. This could potentially be exploited by other attackers if the administrator ignores a security warning on the permissions assignment page.
Recommendations For Flag module versions 7.x-3.0 through 7.x-3.5, consider disabling the flag import form validate function until a patch is available to prevent exploitation. Restrict access to the /admin/structure/flags/import endpoint to minimize the risk of arbitrary PHP code execution. Avoid using the Flag import code text area in the affected endpoint until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3453

Produtos afetados

Flag