PT-2019-9608 · Oscommerce · Oscommerce
Hexifeo
·
Published
2019-08-22
·
Updated
2019-08-28
·
CVE-2018-18573
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
osCommerce version 2.3.4.1
Description
The issue is related to an incomplete '.htaccess' file for blacklist filtering in the product page, allowing remote authenticated administrators to upload new '.htaccess' files. This can lead to arbitrary PHP code execution via the "/catalog/admin/categories.php?cPath=&action=new product" API endpoint, specifically by manipulating the
cPath and action variables.Recommendations
For osCommerce version 2.3.4.1, restrict access to the "/catalog/admin/categories.php" API endpoint to prevent arbitrary PHP code execution. As a temporary workaround, consider disabling the product upload feature for administrators until a proper fix is applied. Ensure that all '.htaccess' files are properly configured to prevent malicious uploads.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oscommerce