PT-2018-11466 · Webgrind · Webgrind

Abhikafle123

·

Publicado

2018-06-27

·

Atualizado

2024-08-05

·

CVE-2018-12909

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Webgrind version 1.5
Description The issue allows anyone to view files from the local filesystem that the webserver user has access to. This is achieved by manipulating the file parameter in the /index.php API endpoint, specifically through the op=fileviewer&file= URI. It is noted that the vendor does not intend the product for use in a publicly accessible environment.
Recommendations For Webgrind version 1.5, as a temporary workaround, consider restricting access to the fileviewer operation in the index.php endpoint to minimize the risk of exploitation. Avoid using the file parameter in the affected API endpoint until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-8422
CVE-2018-12909

Produtos afetados

Webgrind