PT-2018-15157 · Apache+1 · Freemarker+1

Buxuo

·

Publicado

2018-12-06

·

Atualizado

2018-12-26

·

CVE-2018-19907

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crafter CMS version 3.0.18
Description A Server-Side Template Injection issue allows attackers with developer privileges to execute OS commands by creating or editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.
Recommendations For Crafter CMS version 3.0.18, consider restricting access to template file creation and editing to prevent potential exploitation until a patch is available. As a temporary workaround, consider disabling the use of the FreeMarker library or restricting its functionality to minimize the risk of OS command execution.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19907
GHSA-9FCP-VCQ9-9H2H

Produtos afetados

Crafter Cms
Freemarker