PT-2019-7748 · Cysteme · Cysteme-Finder Plugin

To-Mos

·

Published

2019-09-13

·

Updated

2019-09-13

·

CVE-2016-10955

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cysteme-finder plugin versions prior to 1.4
Description The issue is related to unrestricted file upload due to incorrect session tracking. This allows for potential security breaches.
Recommendations For versions prior to 1.4, update to version 1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the file upload functionality until the update is applied.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10955

Affected Products

Cysteme-Finder Plugin