PT-2018-15260 · Zzzphp · Zzzphp Cms
Published
2018-12-13
·
Updated
2020-07-14
·
CVE-2018-20127
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
zzzphp cms version 1.5.8
Description
An issue was discovered that allows remote attackers to delete arbitrary files. This is possible due to the
del file function in the /admin/save.php endpoint, which can be exploited by using a mixed-case extension and an extra '.' character. For example, while "php" is blocked, a path like "F:/1.phP" can succeed.Recommendations
For zzzphp cms version 1.5.8, consider restricting access to the
del file function in the /admin/save.php endpoint until a patch is available. As a temporary workaround, avoid using mixed-case extensions in file paths to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zzzphp Cms