PT-2015-2905 · 1С Битрикс · Bitrix.Mpbuilder

Published

2015-12-16

·

Updated

2018-10-09

·

CVE-2015-8358

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions bitrix.mpbuilder module versions prior to 1.0.12
Description The issue exists due to insufficient restriction of the directory path name in the bitrix.mpbuilder module of the 1С-Битрикс system. Exploitation of this issue may allow a remote attacker to include and execute arbitrary local files by adding ".." symbols to the directory name in the "work" array parameter to the "admin/bitrix.mpbuilder step2.php" endpoint.
Recommendations For versions prior to 1.0.12, update to version 1.0.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the "admin/bitrix.mpbuilder step2.php" endpoint to minimize the risk of exploitation. Avoid using the work array parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00002
CVE-2015-8358

Affected Products

Bitrix.Mpbuilder