PT-2018-13807 · Elefant · Elefant Cms

Liao10086

·

Published

2018-09-12

·

Updated

2022-05-13

·

CVE-2018-16975

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elefant CMS versions prior to 2.0.7
Description The issue is related to a PHP Code Execution Vulnerability. It can be exploited through the /designer/add/stylesheet.php endpoint by using a .php extension in the New Stylesheet Name field in conjunction with <?php content. This is due to insufficient input validation in apps/designer/handlers/csspreview.php.
Recommendations For versions prior to 2.0.7, update to version 2.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the /designer/add/stylesheet.php endpoint or disabling the apps/designer/handlers/csspreview.php handler until a patch is available. Avoid using the .php extension in the New Stylesheet Name field to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16975
GHSA-X2W2-QGV6-8XRM

Affected Products

Elefant Cms