PT-2019-14569 · Doccms · Doccms
Published
2019-09-09
·
Updated
2020-08-24
·
CVE-2019-16192
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DocCms version 2016.5.17
Description
The issue allows remote attackers to execute arbitrary PHP code through module management files. This can be achieved by uploading a .php file in a ZIP archive, exploiting the
upload model() function in the /admini/controllers/system/managemodel.php file.Recommendations
For DocCms version 2016.5.17, consider disabling the
upload model() function in the /admini/controllers/system/managemodel.php file as a temporary workaround to prevent exploitation. Restrict access to module management files to minimize the risk of arbitrary PHP code execution. Avoid using the module management feature until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Doccms