PT-2019-19310 · Mopcms · Mopcms
Publicado
2019-02-22
·
Atualizado
2019-02-22
·
CVE-2019-9015
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MOPCMS versions prior to 2018-11-30
Description
A Path Traversal issue was discovered, allowing the deletion of critical files. The issue is related to the "column management" function, where the path added to the column is not verified. This can be exploited by deleting a column, which in turn deletes the corresponding directory. For example, using ./ can lead to the deletion of the entire website.
Recommendations
For versions prior to 2018-11-30, as a temporary workaround, consider restricting access to the "column management" function until a fix is available. Avoid using the column deletion feature in the affected function to minimize the risk of exploitation.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mopcms