PT-2019-14776 · Unknown · Slub Events
Torben Hansen
·
Published
2019-10-16
·
Updated
2022-05-24
·
CVE-2019-16700
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
slub events extension versions 1.2.2 and earlier
slub events extension versions later than 1.2.2 through 3.0.2
Description
The issue allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with arbitrary files.
Recommendations
For versions 1.2.2 and earlier, update to a version later than 1.2.2 to prevent Remote Code Execution.
For versions later than 1.2.2 through 3.0.2, restrict file upload capabilities to prevent Denial of Service.
As a temporary workaround, consider disabling file upload functionality until a patch is available.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slub Events