PT-2019-14376 · Kslabs · Ksweb
Published
2019-10-03
·
Updated
2021-07-21
·
CVE-2019-15766
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KSLABS KSWEB (aka ru.kslabs.ksweb) version 3.93
Description
The issue allows authenticated remote code execution via a POST request to the AJAX handler with the
configFile parameter set to the arbitrary file to be written to, and the config text parameter set to the content of the file to be created. This can result in a PHP file being written to the public web directory and subsequently executed. The attacker must have network connectivity to the PHP server running on the Android device.Recommendations
For KSLABS KSWEB version 3.93, as a temporary workaround, consider restricting access to the AJAX handler and limiting the ability to set the
configFile and config text parameters to prevent arbitrary file creation. Additionally, restrict execution of PHP files in the public web directory to minimize the risk of exploitation.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ksweb