PT-2018-13109 · Elefant · Elefant Cms

Publicado

2018-08-21

·

Atualizado

2022-05-14

·

CVE-2018-15601

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elefant CMS version 2.0.3
Description The issue arises from the apps/filemanager/handlers/upload/drop.php file in Elefant CMS, where a urldecode step is performed too late in the protection mechanism against uploading executable files. This could potentially allow malicious files to be uploaded.
Recommendations For Elefant CMS version 2.0.3, consider disabling the drop.php handler in the file manager until a patch is available to address the issue with the urldecode step timing. Restrict access to the file upload functionality to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15601
GHSA-PCF7-5974-VJH4

Produtos afetados

Elefant Cms