PT-2018-13109 · Elefant · Elefant Cms
Published
2018-08-21
·
Updated
2022-05-14
·
CVE-2018-15601
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Elefant CMS version 2.0.3
Description
The issue arises from the
apps/filemanager/handlers/upload/drop.php file in Elefant CMS, where a urldecode step is performed too late in the protection mechanism against uploading executable files. This could potentially allow malicious files to be uploaded.Recommendations
For Elefant CMS version 2.0.3, consider disabling the
drop.php handler in the file manager until a patch is available to address the issue with the urldecode step timing. Restrict access to the file upload functionality to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elefant Cms