PT-2019-19268 · Dedecms · Dedecms

Publicado

2019-02-19

·

Atualizado

2019-02-20

·

CVE-2019-8933

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS version 5.7SP2
Description The issue allows attackers to upload a .php file to the uploads/ directory and then execute it. This can be achieved by visiting the management page, clicking on the template, clicking on Default Template Management, clicking on New Template, and modifying the filename from ../index.html to ../index.php.
Recommendations For DedeCMS version 5.7SP2, consider restricting access to the template management functionality and the uploads/ directory to prevent unauthorized file uploads and executions. As a temporary workaround, consider disabling the template upload feature until a patch is available.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-8933

Produtos afetados

Dedecms