PT-2017-13300 · Squiz · Squiz Matrix

Publicado

2017-11-30

·

Atualizado

2019-10-03

·

CVE-2017-14198

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Squiz Matrix versions prior to 5.3.6.1 Squiz Matrix versions 5.4.x prior to 5.4.1.3
Description An issue allows authenticated users with permissions to edit design assets to cause Remote Code Execution (RCE) via a maliciously crafted time format tag.
Recommendations For Squiz Matrix versions prior to 5.3.6.1, update to version 5.3.6.1 or later. For Squiz Matrix versions 5.4.x prior to 5.4.1.3, update to version 5.4.1.3 or later.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14198

Produtos afetados

Squiz Matrix