PT-2019-19422 · Bolt · Bolt
Medu554
·
Publicado
2019-03-07
·
Atualizado
2022-05-13
·
CVE-2019-9185
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bolt versions prior to 3.6.5
Description
The issue allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension. This is possible due to a flaw in the
Controller/Async/FilesystemManager.php file in the filemanager.Recommendations
For versions prior to 3.6.5, update to version 3.6.5 or later to resolve the issue. As a temporary workaround, consider restricting file upload and rename capabilities to minimize the risk of exploitation. Avoid allowing users to upload files with .php extensions until the issue is resolved.
Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bolt