PT-2018-13459 · Phpkaiyuancms · Phpkaiyuancms Phpopensourcecms

Howchen

·

Publicado

2018-08-31

·

Atualizado

2018-10-23

·

CVE-2018-16278

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpkaiyuancms PhpOpenSourceCMS (POSCMS) version 3.2.0
Description The issue allows an unauthenticated user to execute arbitrary SQL commands. This is achieved via the "diy/module/member/controllers/Api.php" file, specifically through the ajax save draft function, by manipulating the dir parameter.
Recommendations For phpkaiyuancms PhpOpenSourceCMS (POSCMS) version 3.2.0, consider restricting access to the ajax save draft function in the Api.php file until a patch is available. As a temporary workaround, avoid using the dir parameter in the affected API endpoint.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16278

Produtos afetados

Phpkaiyuancms Phpopensourcecms