PT-2014-2911 · Sharetronix · Sharetronix

Published

2014-06-13

·

Updated

2017-08-29

·

CVE-2013-5352

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sharetronix versions 3.1.1.3, 3.1.1, and earlier
Description The issue allows remote attackers to execute arbitrary PHP code. This is achieved via two parameters: activities text to the "services/activities/set" endpoint or comments text to the "services/comments/set" endpoint. The vulnerability arises from improper handling when executing the preg replace function with the e modifier.
Recommendations For Sharetronix versions 3.1.1.3, 3.1.1, and earlier, consider disabling the preg replace function with the e modifier until a patch is available. Restrict access to the "services/activities/set" and "services/comments/set" endpoints to minimize the risk of exploitation. Avoid using the activities text and comments text parameters in the affected endpoints until the issue is resolved.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5352

Affected Products

Sharetronix