PT-2019-12268 · Wcms · Wcms
Yu Yang
·
Published
2019-04-20
·
Updated
2019-04-22
·
CVE-2019-11377
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WCMS version 0.3.2
Description
The issue concerns an arbitrary file upload vulnerability. This is due to the
fm get text exts function considering .php as a valid extension, allowing for potential malicious file uploads via the developer/finder component.Recommendations
For WCMS version 0.3.2, consider restricting or disabling the file upload functionality in the
developer/finder component until a proper fix is available. Additionally, review and modify the fm get text exts function to exclude .php from valid extensions to prevent malicious uploads.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wcms