PT-2019-18702 · Inxedu · Inxedu

Ziliudi

·

Publicado

2019-02-09

·

Atualizado

2019-02-22

·

CVE-2019-7684

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions inxedu through 2018-12-24
Description The issue allows an attacker to upload a malicious JSP file. This is achieved by exploiting the fileType parameter in the /video/uploadvideo API endpoint to modify the list of acceptable file extensions from jpg,gif,png,jpeg to jpg,gif,png,jsp,jpeg. The vulnerable code is located in the com.inxedu.os.common.controller.VideoUploadController class, specifically in the gok4 method.
Recommendations For inxedu through 2018-12-24, consider restricting access to the /video/uploadvideo API endpoint to prevent the upload of malicious JSP files until a fix is available. Additionally, as a temporary workaround, restrict the fileType parameter to only allow the original list of acceptable extensions: jpg,gif,png,jpeg.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-7684

Produtos afetados

Inxedu