PT-2017-14636 · Finecms · Finecms

Published

2017-11-21

·

Updated

2019-10-03

·

CVE-2017-16920

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FineCms version 5.2.0
Description The issue allows remote attackers to upload arbitrary .php files. This is possible due to a default SYS KEY value in the v5/config/system.php file, which does not require key regeneration for each installation. Attackers can exploit this via a member API swfupload action to index.php.
Recommendations For FineCms version 5.2.0, consider regenerating the SYS KEY value for each installation to prevent the use of a default key, and restrict access to the swfupload action in index.php to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-16920

Affected Products

Finecms