PT-2019-12422 · Doorgets · Doorgets

Published

2019-04-30

·

Updated

2019-05-01

·

CVE-2019-11615

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions doorGets version 7.0
Description The issue allows a remote normal registered user to upload arbitrary files, potentially including backdoor files, to control the server. This is due to a vulnerability in the /fileman/php/upload.php endpoint.
Recommendations For doorGets version 7.0, consider restricting access to the /fileman/php/upload.php endpoint until a patch is available. As a temporary workaround, restrict file uploads to only necessary and trusted users to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11615

Affected Products

Doorgets