PT-2018-12833 · Isweb · Cms Isweb
Rafael Fontes Souza
+1
·
Published
2018-09-28
·
Updated
2018-12-19
·
CVE-2018-14957
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CMS ISWEB version 3.5.3
Description
The issue allows for directory traversal and local file download. This can be demonstrated through the "moduli/downloadFile.php" endpoint with a
file parameter set to oggetto documenti/../.././inc/config.php, potentially allowing an attacker to gain control of the application due to credentials being present in the config.php file.Recommendations
For CMS ISWEB version 3.5.3, consider restricting access to the
moduli/downloadFile.php endpoint or implementing validation on the file parameter to prevent directory traversal attacks. As a temporary workaround, consider removing or securing the config.php file to prevent credential exposure until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cms Isweb