PT-2019-14776 · Unknown · Slub Events
Torben Hansen
·
Publicado
2019-10-16
·
Atualizado
2022-05-24
·
CVE-2019-16700
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
slub events extension versions 1.2.2 and earlier
slub events extension versions later than 1.2.2 through 3.0.2
Description
The issue allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with arbitrary files.
Recommendations
For versions 1.2.2 and earlier, update to a version later than 1.2.2 to prevent Remote Code Execution.
For versions later than 1.2.2 through 3.0.2, restrict file upload capabilities to prevent Denial of Service.
As a temporary workaround, consider disabling file upload functionality until a patch is available.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Slub Events