PT-2019-13981 · Artica · Artica Integria Ims
A Guest
·
Publicado
2019-08-16
·
Atualizado
2019-08-27
·
CVE-2019-15091
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Artica Integria IMS version 5.0.86
Description
The issue allows for arbitrary file upload through the filemgr.php script in the wiki operation section. This is achieved by accessing the "index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload" API endpoint. The
action parameter is set to upload, which enables the file upload functionality.Recommendations
For Artica Integria IMS version 5.0.86, consider disabling the file upload functionality in the wiki operation section until a patch is available. Restrict access to the filemgr.php script to minimize the risk of exploitation. Avoid using the
action parameter set to upload in the affected API endpoint until the issue is resolved.Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Artica Integria Ims