PT-2018-3785 · Sdcms · Sdcms

Publicado

2018-11-25

·

Atualizado

2019-02-04

·

CVE-2018-19520

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SDCMS version 1.6
Description The issue is related to incorrect code generation management in SDCMS, allowing remote attackers to execute arbitrary PHP code. Specifically, the themecontroller.php file in the app/admin/controller directory uses a check bad function to block certain PHP functions, such as eval, but fails to prevent the use of preg replace 'e' calls. This oversight enables users to execute arbitrary code by leveraging access to admin template management.
Recommendations For SDCMS version 1.6, consider disabling the themecontroller.php file or restricting access to admin template management until a patch is available. Additionally, as a temporary workaround, avoid using the preg replace function with the 'e' modifier in the affected themecontroller.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02427
CVE-2018-19520

Produtos afetados

Sdcms