PT-2023-11588 · Unknown · Nucleus Cms

Gsuhy-Lo

·

Publicado

2023-06-20

·

Atualizado

2024-12-10

·

CVE-2020-21474

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NucleusCMS version 3.71
Description The issue allows a remote attacker to execute arbitrary code. This is achieved via the "https://example.com/nucleus/plugins/skinfiles/?dir=rsd" API endpoint, where the dir parameter is set to rsd.
Recommendations For NucleusCMS version 3.71, consider disabling the file upload functionality until a patch is available. Restrict access to the /nucleus/plugins/skinfiles/ API endpoint to minimize the risk of exploitation. Avoid using the dir parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-21474

Produtos afetados

Nucleus Cms