PT-2023-32791 · Kalcaddle · Kodexplorer
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
kalcaddle KodExplorer versions up to 4.51.03
Description
A critical issue affects the API Endpoint Handler component, specifically the /index.php?pluginApp/to/yzOffice/getFile file. The manipulation of the
path/file argument leads to unrestricted upload. This issue can be exploited remotely.Recommendations
For versions up to 4.51.03, upgrade to version 4.52.01 to address this issue. As a temporary workaround, consider restricting access to the
/index.php?pluginApp/to/yzOffice/getFile API endpoint until the upgrade is applied. Additionally, avoid using the path/file argument in the affected API endpoint until the issue is resolved.Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kodexplorer