PT-2018-11496 · Seeddms · Seeddms

Published

2018-07-31

·

Updated

2018-10-01

·

CVE-2018-12940

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeedDMS versions prior to 5.1.8
Description The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the qqfile parameter. This enables an authenticated attacker to upload a malicious file containing PHP code, which can then be used to execute operating system commands to the web root of the application.
Recommendations For versions prior to 5.1.8, update to version 5.1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the "op/op.UploadChunks.php" file to minimize the risk of exploitation. Avoid using the qqfile parameter in the affected upload functionality until the issue is resolved.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12940

Affected Products

Seeddms