PT-2018-11496 · Seeddms · Seeddms

Publicado

2018-07-31

·

Atualizado

2018-10-01

·

CVE-2018-12940

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeedDMS versions prior to 5.1.8
Description The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the qqfile parameter. This enables an authenticated attacker to upload a malicious file containing PHP code, which can then be used to execute operating system commands to the web root of the application.
Recommendations For versions prior to 5.1.8, update to version 5.1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the "op/op.UploadChunks.php" file to minimize the risk of exploitation. Avoid using the qqfile parameter in the affected upload functionality until the issue is resolved.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12940

Produtos afetados

Seeddms