PT-2019-13981 · Artica · Artica Integria Ims

A Guest

·

Published

2019-08-16

·

Updated

2019-08-27

·

CVE-2019-15091

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artica Integria IMS version 5.0.86
Description The issue allows for arbitrary file upload through the filemgr.php script in the wiki operation section. This is achieved by accessing the "index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload" API endpoint. The action parameter is set to upload, which enables the file upload functionality.
Recommendations For Artica Integria IMS version 5.0.86, consider disabling the file upload functionality in the wiki operation section until a patch is available. Restrict access to the filemgr.php script to minimize the risk of exploitation. Avoid using the action parameter set to upload in the affected API endpoint until the issue is resolved.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15091

Affected Products

Artica Integria Ims