PT-2018-9259 · Ajenti · Ajenti
Published
2018-03-13
·
Updated
2019-10-03
·
CVE-2018-1000080
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Ajenti version 2
Description:
The issue concerns an Insecure Permissions vulnerability in the Plugins download feature. This vulnerability can allow the download of any plugins as a normal user. The attack is exploitable by understanding how the requisition is made and sending it as a normal user, which results in the server downloading the plugin in response.
Recommendations:
For Ajenti version 2, consider restricting access to the plugin download feature to prevent exploitation until a proper fix is available. As a temporary workaround, restrict the permissions of normal users to minimize the risk of unauthorized plugin downloads.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ajenti