PT-2019-14792 · Zzcms · Zzcms
Published
2019-09-23
·
Updated
2019-09-23
·
CVE-2019-16720
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ZZZCMS zzzphp version 1.7.2
Description
The issue concerns a lack of proper restriction on file uploads in the plugins/ueditor/php/controller.php endpoint, specifically when the "upfolder" parameter is set to "news" and the "action" parameter is set to "catchimage". This allows for the upload of malicious files, such as .htaccess or .php5 files.
Recommendations
For ZZZCMS zzzphp version 1.7.2, consider restricting access to the "upfolder=news&action=catchimage" endpoint in the plugins/ueditor/php/controller.php file to prevent malicious file uploads. As a temporary workaround, consider disabling the file upload functionality in this endpoint until a proper fix is available.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zzcms