PT-2020-10307 · Selesta · Selesta Visual Access Manager
Published
2020-02-26
·
Updated
2020-02-27
·
CVE-2019-19988
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Selesta Visual Access Manager (VAM) versions 4.15.0 through 4.29
Description
An issue allows a user with valid credentials to create and write XML files on the filesystem via the "/common/vam editXml.php" API endpoint in the web interface. The vulnerable PHP page does not check the
file name parameter, the destination path, or the file extension, enabling an attacker to manipulate the file name and create any type of file within the filesystem with arbitrary content.Recommendations
For versions 4.15.0 through 4.29, as a temporary workaround, consider restricting access to the "/common/vam editXml.php" API endpoint to minimize the risk of exploitation. Additionally, restrict the ability to create files with arbitrary extensions and content to prevent potential attacks.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Selesta Visual Access Manager