PT-2020-10307 · Selesta · Selesta Visual Access Manager

Published

2020-02-26

·

Updated

2020-02-27

·

CVE-2019-19988

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Selesta Visual Access Manager (VAM) versions 4.15.0 through 4.29
Description An issue allows a user with valid credentials to create and write XML files on the filesystem via the "/common/vam editXml.php" API endpoint in the web interface. The vulnerable PHP page does not check the file name parameter, the destination path, or the file extension, enabling an attacker to manipulate the file name and create any type of file within the filesystem with arbitrary content.
Recommendations For versions 4.15.0 through 4.29, as a temporary workaround, consider restricting access to the "/common/vam editXml.php" API endpoint to minimize the risk of exploitation. Additionally, restrict the ability to create files with arbitrary extensions and content to prevent potential attacks.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19988

Affected Products

Selesta Visual Access Manager