PT-2018-9259 · Ajenti · Ajenti

Published

2018-03-13

·

Updated

2019-10-03

·

CVE-2018-1000080

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Ajenti version 2
Description: The issue concerns an Insecure Permissions vulnerability in the Plugins download feature. This vulnerability can allow the download of any plugins as a normal user. The attack is exploitable by understanding how the requisition is made and sending it as a normal user, which results in the server downloading the plugin in response.
Recommendations: For Ajenti version 2, consider restricting access to the plugin download feature to prevent exploitation until a proper fix is available. As a temporary workaround, restrict the permissions of normal users to minimize the risk of unauthorized plugin downloads.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000080
PYSEC-2018-109

Affected Products

Ajenti