PT-2019-12286 · Siteserver · Siteserver Cms

Diy0829

·

Published

2019-04-21

·

Updated

2022-05-24

·

CVE-2019-11401

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiteServer CMS versions 6.9.0 through 6.11
Description A issue was discovered in SiteServer CMS that allows remote attackers to execute arbitrary code. This is possible because an administrator can add the permitted file extension .aassp, which is converted to .asp due to the deletion of the "as" substring.
Recommendations For SiteServer CMS versions 6.9.0 through 6.11, update to version 6.12 or later to resolve the issue.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11401
GHSA-FF4W-8CHR-W2X9

Affected Products

Siteserver Cms