PT-2016-7338 · Pixidou+1 · Pixidou Image Editor+1

Manuel Garcia Cardenas

·

Publicado

2016-11-03

·

Atualizado

2018-02-27

·

CVE-2016-7452

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Exponent CMS versions prior to 2.3.9 patch 2
Description The issue allows an attacker to upload a malicious file to any folder on the site via a cpi directory traversal in the Pixidou Image Editor.
Recommendations For versions prior to 2.3.9 patch 2, update to version 2.3.9 patch 2 or later to resolve the issue.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7452

Produtos afetados

Exponent Cms
Pixidou Image Editor