PT-2019-14792 · Zzcms · Zzcms

Published

2019-09-23

·

Updated

2019-09-23

·

CVE-2019-16720

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZZZCMS zzzphp version 1.7.2
Description The issue concerns a lack of proper restriction on file uploads in the plugins/ueditor/php/controller.php endpoint, specifically when the "upfolder" parameter is set to "news" and the "action" parameter is set to "catchimage". This allows for the upload of malicious files, such as .htaccess or .php5 files.
Recommendations For ZZZCMS zzzphp version 1.7.2, consider restricting access to the "upfolder=news&action=catchimage" endpoint in the plugins/ueditor/php/controller.php file to prevent malicious file uploads. As a temporary workaround, consider disabling the file upload functionality in this endpoint until a proper fix is available.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16720

Affected Products

Zzcms