PT-2019-15825 · Squiz · Squiz Matrix Cms

Stephen Shkardoon

·

Publicado

2019-12-11

·

Atualizado

2020-08-24

·

CVE-2019-19374

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Squiz Matrix CMS versions 5.5.0 through 5.5.0.2 Squiz Matrix CMS versions 5.5.1 through 5.5.1.7 Squiz Matrix CMS versions 5.5.2 through 5.5.2.3 Squiz Matrix CMS versions 5.5.3 through 5.5.3.2
Description An issue in the File Upload field type allows users to delete arbitrary files from the server and view the full path to uploaded files, including the product's web root directory, when a custom form exists.
Recommendations For Squiz Matrix CMS versions 5.5.0 through 5.5.0.2, update to version 5.5.0.3 or later. For Squiz Matrix CMS versions 5.5.1 through 5.5.1.7, update to version 5.5.1.8 or later. For Squiz Matrix CMS versions 5.5.2 through 5.5.2.3, update to version 5.5.2.4 or later. For Squiz Matrix CMS versions 5.5.3 through 5.5.3.2, update to version 5.5.3.3 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19374

Produtos afetados

Squiz Matrix Cms