PT-2007-2556 · Mtcms · Mtcms

Published

2007-02-27

·

Updated

2018-10-16

·

CVE-2007-1129

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MTCMS version 3.2
Description The issue allows remote attackers to upload and execute files due to unrestricted file upload vulnerabilities. This can be achieved via an avatar upload in an add down action or an add link action.
Recommendations For MTCMS version 3.2, consider restricting or disabling the file upload functionality in the add down and add link actions until a patch is available. Additionally, restrict access to the affected areas to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1129

Affected Products

Mtcms