PT-2019-19723 · Phpscheduleit · Phpscheduleit Booked Scheduler

Akkus

+1

·

Publicado

2019-03-06

·

Atualizado

2022-03-31

·

CVE-2019-9581

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpscheduleit Booked Scheduler version 2.7.5
Description The issue allows for arbitrary file upload through the Favicon field. This can lead to the execution of arbitrary PHP code in Web/custom-favicon.php, because the ManageThemePresenter.php file in the Presenters/Admin directory does not properly validate image file extensions.
Recommendations For version 2.7.5, ensure that the Favicon field properly validates and restricts file uploads to only image file extensions to prevent arbitrary PHP code execution. As a temporary workaround, consider disabling the Favicon upload feature until a proper fix is applied.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9581

Produtos afetados

Phpscheduleit Booked Scheduler