PT-2018-13109 · Elefant · Elefant Cms
Publicado
2018-08-21
·
Atualizado
2022-05-14
·
CVE-2018-15601
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Elefant CMS version 2.0.3
Description
The issue arises from the
apps/filemanager/handlers/upload/drop.php file in Elefant CMS, where a urldecode step is performed too late in the protection mechanism against uploading executable files. This could potentially allow malicious files to be uploaded.Recommendations
For Elefant CMS version 2.0.3, consider disabling the
drop.php handler in the file manager until a patch is available to address the issue with the urldecode step timing. Restrict access to the file upload functionality to minimize the risk of exploitation.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Elefant Cms