PT-2007-2556 · Mtcms · Mtcms
Published
2007-02-27
·
Updated
2018-10-16
·
CVE-2007-1129
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MTCMS version 3.2
Description
The issue allows remote attackers to upload and execute files due to unrestricted file upload vulnerabilities. This can be achieved via an avatar upload in an add down action or an add link action.
Recommendations
For MTCMS version 3.2, consider restricting or disabling the file upload functionality in the add down and add link actions until a patch is available. Additionally, restrict access to the affected areas to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mtcms