PT-2018-13109 · Elefant · Elefant Cms

Published

2018-08-21

·

Updated

2022-05-14

·

CVE-2018-15601

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elefant CMS version 2.0.3
Description The issue arises from the apps/filemanager/handlers/upload/drop.php file in Elefant CMS, where a urldecode step is performed too late in the protection mechanism against uploading executable files. This could potentially allow malicious files to be uploaded.
Recommendations For Elefant CMS version 2.0.3, consider disabling the drop.php handler in the file manager until a patch is available to address the issue with the urldecode step timing. Restrict access to the file upload functionality to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15601
GHSA-PCF7-5974-VJH4

Affected Products

Elefant Cms