PT-2019-12662 · Karamasoft · Karamasoft Ultimateeditor

Arvin Christopher Moreno

·

Publicado

2019-05-24

·

Atualizado

2019-05-30

·

CVE-2019-12150

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Karamasoft UltimateEditor version 1
Description The issue allows an attacker to upload files without restrictions on file types or extensions. The upload can be performed using the Attach icon. Once uploaded, the files are accessible under the UltimateEditorInclude/UserFiles/ URI.
Recommendations For Karamasoft UltimateEditor version 1, restrict access to the Attach icon to prevent unauthorized file uploads, and consider implementing file type and extension restrictions to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12150

Produtos afetados

Karamasoft Ultimateeditor