PT-2019-14776 · Unknown · Slub Events

Torben Hansen

·

Published

2019-10-16

·

Updated

2022-05-24

·

CVE-2019-16700

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions slub events extension versions 1.2.2 and earlier slub events extension versions later than 1.2.2 through 3.0.2
Description The issue allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with arbitrary files.
Recommendations For versions 1.2.2 and earlier, update to a version later than 1.2.2 to prevent Remote Code Execution. For versions later than 1.2.2 through 3.0.2, restrict file upload capabilities to prevent Denial of Service. As a temporary workaround, consider disabling file upload functionality until a patch is available.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16700
GHSA-5PWW-3MFC-G8VR

Affected Products

Slub Events