PT-2019-12641 · Kentico · Kentico
CVE-2019-12102
·
Publicado
2019-05-22
·
Atualizado
2024-08-04
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kentico versions 11 through 12
Description
The issue allows attackers to upload and explore files without authentication via the "cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs media.aspx" URI. However, the vendor disputes this report, stating that the media library permissions were not configured correctly by the researcher. By default, all users can read, modify, and upload files, and it is up to the administrator to decide who should have access to the media library and set the permissions accordingly.
Recommendations
For Kentico versions 11 through 12, ensure that the media library permissions are configured correctly to restrict access to authorized users. Administrators should review and set the permissions according to their requirements to prevent unauthorized file uploads and exploration.
Exploit
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kentico