PT-2019-19310 · Mopcms · Mopcms

Published

2019-02-22

·

Updated

2019-02-22

·

CVE-2019-9015

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions MOPCMS versions prior to 2018-11-30
Description A Path Traversal issue was discovered, allowing the deletion of critical files. The issue is related to the "column management" function, where the path added to the column is not verified. This can be exploited by deleting a column, which in turn deletes the corresponding directory. For example, using ./ can lead to the deletion of the entire website.
Recommendations For versions prior to 2018-11-30, as a temporary workaround, consider restricting access to the "column management" function until a fix is available. Avoid using the column deletion feature in the affected function to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9015

Affected Products

Mopcms