PT-2019-12641 · Kentico · Kentico

CVE-2019-12102

·

Publicado

2019-05-22

·

Atualizado

2024-08-04

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kentico versions 11 through 12
Description The issue allows attackers to upload and explore files without authentication via the "cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs media.aspx" URI. However, the vendor disputes this report, stating that the media library permissions were not configured correctly by the researcher. By default, all users can read, modify, and upload files, and it is up to the administrator to decide who should have access to the media library and set the permissions accordingly.
Recommendations For Kentico versions 11 through 12, ensure that the media library permissions are configured correctly to restrict access to authorized users. Administrators should review and set the permissions according to their requirements to prevent unauthorized file uploads and exploration.

Exploit

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12102

Produtos afetados

Kentico