PT-2019-13981 · Artica · Artica Integria Ims

A Guest

·

Publicado

2019-08-16

·

Atualizado

2019-08-27

·

CVE-2019-15091

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artica Integria IMS version 5.0.86
Description The issue allows for arbitrary file upload through the filemgr.php script in the wiki operation section. This is achieved by accessing the "index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload" API endpoint. The action parameter is set to upload, which enables the file upload functionality.
Recommendations For Artica Integria IMS version 5.0.86, consider disabling the file upload functionality in the wiki operation section until a patch is available. Restrict access to the filemgr.php script to minimize the risk of exploitation. Avoid using the action parameter set to upload in the affected API endpoint until the issue is resolved.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15091

Produtos afetados

Artica Integria Ims