PT-2018-9518 · Gig Technology Nv · Jumpscale Portal

Vrico315

·

Published

2018-09-06

·

Updated

2019-03-07

·

CVE-2018-1000666

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIG Technology NV JumpScale Portal 7 versions before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb
Description The issue is related to an OS Command Injection vulnerability in the notifySpaceModification method. This vulnerability can result in improper validation of parameters, leading to command execution. The attack appears to be exploitable via network connectivity and requires minimal authentication privileges, as everyone can register an account.
Recommendations For GIG Technology NV JumpScale Portal 7 versions before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb, update to a version after commit 15443122ed2b1cbfd7bdefc048bf106f075becdb to resolve the issue. As a temporary workaround, consider restricting access to the notifySpaceModification method until a patch is available.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000666

Affected Products

Jumpscale Portal