PT-2018-11497 · Seeddms · Seeddms

Published

2018-07-31

·

Updated

2018-10-09

·

CVE-2018-12941

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SeedDMS versions prior to 5.1.8
Description This issue allows remote attackers to execute arbitrary code by manipulating the cacheDir path and using the "Clear Cache" functionality. An authenticated attacker with permission to the Settings functionality can inject arbitrary system commands within the application. This can be used to extract, change, or delete sensitive information or run system commands on the underlying operating system.
Recommendations For versions prior to 5.1.8, update to version 5.1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the Settings functionality and the "Clear Cache" option to minimize the risk of exploitation. Avoid manipulating the cacheDir path until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12941

Affected Products

Seeddms