PT-2017-12141 · Fiyo · Fiyo Cms

Rai4Over

·

Publicado

2017-07-26

·

Atualizado

2017-07-31

·

CVE-2017-11630

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fiyo CMS version 2.0.7
Description The issue allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request to the /dapur/apps/app config/controller/backuper.php endpoint.
Recommendations For Fiyo CMS version 2.0.7, restrict access to the backuper.php file to minimize the risk of exploitation. Avoid using the file parameter in the affected endpoint until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11630

Produtos afetados

Fiyo Cms