PT-2019-15233 · Qibosoft · Qibosoft

Publicado

2019-10-15

·

Atualizado

2019-10-18

·

CVE-2019-17613

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions qibosoft version 7
Description The issue allows remote code execution due to the use of eval calls in the do/jf.php file. An attacker can exploit the Point Introduction Management feature to supply PHP code for evaluation. Additionally, an attacker can perform a CSRF attack by accessing the admin/index.php?lfj=jfadmin&action=addjf endpoint, as demonstrated by a payload in the content parameter.
Recommendations For qibosoft version 7, consider disabling the Point Introduction Management feature and restrict access to the admin/index.php?lfj=jfadmin&action=addjf endpoint to minimize the risk of exploitation. Avoid using the content parameter in the affected endpoint until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17613

Produtos afetados

Qibosoft