PT-2018-3785 · Sdcms · Sdcms
Publicado
2018-11-25
·
Atualizado
2019-02-04
·
CVE-2018-19520
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SDCMS version 1.6
Description
The issue is related to incorrect code generation management in SDCMS, allowing remote attackers to execute arbitrary PHP code. Specifically, the
themecontroller.php file in the app/admin/controller directory uses a check bad function to block certain PHP functions, such as eval, but fails to prevent the use of preg replace 'e' calls. This oversight enables users to execute arbitrary code by leveraging access to admin template management.Recommendations
For SDCMS version 1.6, consider disabling the
themecontroller.php file or restricting access to admin template management until a patch is available. Additionally, as a temporary workaround, avoid using the preg replace function with the 'e' modifier in the affected themecontroller.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sdcms