PT-2019-13493 · Comsenz · Discuz!Ml
Published
2019-07-18
·
Updated
2024-10-04
·
CVE-2019-13956
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Discuz!ML versions 3.2 through 3.4
Description
The issue allows remote attackers to execute arbitrary PHP code via a modified language cookie. This can be achieved by altering the cookie value, for example, changing
4gH4 0df5 language=en to 4gH4 0df5 language=en'.phpinfo().';. The attack vector involves manipulating the language parameter in the cookie to inject malicious PHP code.Recommendations
For Discuz!ML versions 3.2 through 3.4, consider restricting access to the language cookie or implementing input validation to prevent malicious modifications. As a temporary workaround, monitor server logs for suspicious activity related to the language cookie.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discuz!Ml