PT-2018-13709 · Cscms · Cscms
Publicado
2018-09-08
·
Atualizado
2018-10-30
·
CVE-2018-16731
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CScms version 4.1
Description
The issue allows for arbitrary file upload. This can be achieved by modifying the default filetype list, which includes
gif, jpg, and png, to accept other file types, such as php. An attacker can then specify a .php pathname within fileurl JSON data to upload malicious files.Recommendations
For CScms version 4.1, restrict the file types that can be uploaded to prevent arbitrary file upload. As a temporary workaround, consider disabling the file upload feature until a patch is available. Avoid using the
fileurl JSON data to upload files with potentially malicious extensions, such as .php, until the issue is resolved.Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cscms