PT-2019-15909 · Nopcommerce · Nopcommerce

Klezvirus

·

Publicado

2019-12-09

·

Atualizado

2019-12-11

·

CVE-2019-19684

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nopCommerce version 4.2.0
Description The issue allows for privilege escalation through file upload in the Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure. This is possible because it is possible to upload a crafted Facebook Auth plugin.
Recommendations For nopCommerce version 4.2.0, as a temporary workaround, consider disabling the file upload functionality in the PluginController.cs until a patch is available. Restrict access to the Admin/FacebookAuthentication/Configure area to minimize the risk of exploitation. Avoid using the crafted Facebook Auth plugin in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19684

Produtos afetados

Nopcommerce