PT-2019-19749 · Ofcms · Ofcms

匿名

·

Publicado

2019-03-06

·

Atualizado

2019-03-07

·

CVE-2019-9610

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OFCMS versions prior to 1.1.3
Description An issue was discovered related to directory traversal. This issue is connected to the getTemplates function in TemplateController.java and can be exploited through the "/admin/cms/template/getTemplates.html" API endpoint with specific parameters such as res path and up dir.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the getTemplates function in TemplateController.java to minimize the risk of exploitation. Avoid using the res path and up dir parameters in the affected API endpoint until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9610

Produtos afetados

Ofcms