PT-2023-27215 · Unknown · Privateuploader

Spysder

·

Publicado

2023-08-14

·

Atualizado

2023-08-22

·

CVE-2023-40020

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrivateUploader versions prior to 3.2.49
Description PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions, the app/routes/v3/admin.controller.ts file did not correctly verify whether the user was an administrator or moderator, causing the request to continue processing. The response would be a 403 with ADMIN ONLY, however, next() would call, leading to any updates/changes in the route to process.
Recommendations For versions prior to 3.2.49, upgrade to version 3.2.49 to address the issue. As a temporary workaround, consider restricting access to the admin.controller.ts file until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40020
GHSA-VHRW-2472-RRJX

Produtos afetados

Privateuploader