PT-2019-19310 · Mopcms · Mopcms

Publicado

2019-02-22

·

Atualizado

2019-02-22

·

CVE-2019-9015

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions MOPCMS versions prior to 2018-11-30
Description A Path Traversal issue was discovered, allowing the deletion of critical files. The issue is related to the "column management" function, where the path added to the column is not verified. This can be exploited by deleting a column, which in turn deletes the corresponding directory. For example, using ./ can lead to the deletion of the entire website.
Recommendations For versions prior to 2018-11-30, as a temporary workaround, consider restricting access to the "column management" function until a fix is available. Avoid using the column deletion feature in the affected function to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9015

Produtos afetados

Mopcms