PT-2018-18751 · Creditwest Bank · Creditwest Bank Cms Project

Ghost

·

Publicado

2018-03-24

·

Atualizado

2018-04-24

·

CVE-2018-8972

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28
Description The issue allows remote attackers to inject arbitrary PHP code via CSRF in the site configuration update functionality. This can be demonstrated by a PHP shell that calls eval on request parameters.
Recommendations For Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28, consider disabling the site configuration update functionality as a temporary workaround until a patch is available. Restrict access to the eval function to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-8972

Produtos afetados

Creditwest Bank Cms Project