PT-2018-14383 · Bage · Bagecms

Publicado

2018-10-11

·

Atualizado

2018-11-29

·

CVE-2018-18257

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BageCMS version 3.1.3
Description An issue was discovered that allows an attacker to delete any files and folders on the web server via a directory traversal attack using specific URI requests, such as index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../.
Recommendations For BageCMS version 3.1.3, consider restricting access to the index.php endpoint with r=admini/template/batch and parameters command and fileName or folderName to prevent unauthorized file and folder deletion until a patch is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18257

Produtos afetados

Bagecms