PT-2019-14526 · Youphptube · Youphptube
CVE-2019-16124
·
Publicado
2019-09-09
·
Atualizado
2024-02-14
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YouPHPTube version 7.4
Description
The issue arises from the lack of access control in the file install/checkConfiguration.php, allowing anyone to edit the configuration file and potentially insert malicious PHP code.
Recommendations
For YouPHPTube version 7.4, consider restricting access to the install/checkConfiguration.php file until a patch is available, or apply appropriate access controls to prevent unauthorized modifications to the configuration file.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Youphptube