PT-2019-13981 · Artica · Artica Integria Ims
A Guest
·
Published
2019-08-16
·
Updated
2019-08-27
·
CVE-2019-15091
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Artica Integria IMS version 5.0.86
Description
The issue allows for arbitrary file upload through the filemgr.php script in the wiki operation section. This is achieved by accessing the "index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload" API endpoint. The
action parameter is set to upload, which enables the file upload functionality.Recommendations
For Artica Integria IMS version 5.0.86, consider disabling the file upload functionality in the wiki operation section until a patch is available. Restrict access to the filemgr.php script to minimize the risk of exploitation. Avoid using the
action parameter set to upload in the affected API endpoint until the issue is resolved.Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artica Integria Ims