PT-2018-11497 · Seeddms · Seeddms

Publicado

2018-07-31

·

Atualizado

2018-10-09

·

CVE-2018-12941

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SeedDMS versions prior to 5.1.8
Description This issue allows remote attackers to execute arbitrary code by manipulating the cacheDir path and using the "Clear Cache" functionality. An authenticated attacker with permission to the Settings functionality can inject arbitrary system commands within the application. This can be used to extract, change, or delete sensitive information or run system commands on the underlying operating system.
Recommendations For versions prior to 5.1.8, update to version 5.1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the Settings functionality and the "Clear Cache" option to minimize the risk of exploitation. Avoid manipulating the cacheDir path until the issue is resolved.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12941

Produtos afetados

Seeddms