PT-2019-19422 · Bolt · Bolt
Medu554
·
Published
2019-03-07
·
Updated
2022-05-13
·
CVE-2019-9185
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bolt versions prior to 3.6.5
Description
The issue allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension. This is possible due to a flaw in the
Controller/Async/FilesystemManager.php file in the filemanager.Recommendations
For versions prior to 3.6.5, update to version 3.6.5 or later to resolve the issue. As a temporary workaround, consider restricting file upload and rename capabilities to minimize the risk of exploitation. Avoid allowing users to upload files with .php extensions until the issue is resolved.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bolt