PT-2018-10302 · Mybiz · Myprocurenet
Ahmad Ramadhan Amizudin
+3
·
Published
2018-05-14
·
Updated
2019-11-12
·
CVE-2018-11091
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyBiz MyProcureNet version 5.0.0
Description
An issue allows a malicious file to be uploaded to the webserver, enabling an attacker to upload a script and issue operating system commands. This occurs because the
HiddenFieldControlCustomWhiteListedExtensions parameter can be adjusted by an attacker to add arbitrary extensions to the whitelist during upload, allowing malicious files to be uploaded and executed to take over the server.Recommendations
For MyBiz MyProcureNet version 5.0.0, restrict access to the file upload feature and remove any custom extensions from the
HiddenFieldControlCustomWhiteListedExtensions parameter to prevent malicious file uploads. Additionally, consider disabling the file upload feature until a fix is available to prevent exploitation.Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Myprocurenet