PT-2019-19310 · Mopcms · Mopcms
Published
2019-02-22
·
Updated
2019-02-22
·
CVE-2019-9015
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MOPCMS versions prior to 2018-11-30
Description
A Path Traversal issue was discovered, allowing the deletion of critical files. The issue is related to the "column management" function, where the path added to the column is not verified. This can be exploited by deleting a column, which in turn deletes the corresponding directory. For example, using ./ can lead to the deletion of the entire website.
Recommendations
For versions prior to 2018-11-30, as a temporary workaround, consider restricting access to the "column management" function until a fix is available. Avoid using the column deletion feature in the affected function to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mopcms