PT-2017-13312 · Genixcms · Genixcms

Publicado

2017-09-10

·

Atualizado

2022-05-17

·

CVE-2017-14231

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GeniXCMS versions prior to 1.1.0
Description The issue allows remote attackers to cause a denial of service, specifically account blockage, by exploiting the mishandling of certain username substring relationships. This is related to files such as register.php, User.class.php, and Type.class.php.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the registration of usernames that could be leveraged to cause a denial of service, such as those containing specific substrings that could be mishandled by the system.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14231
GHSA-2M9R-PM7Q-WR6F

Produtos afetados

Genixcms