PT-2020-10313 · Selesta · Selesta Visual Access Manager
Published
2020-02-26
·
Updated
2020-02-27
·
CVE-2019-19994
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Selesta Visual Access Manager (VAM) versions 4.15.0 through 4.29
Description
An issue in Selesta Visual Access Manager allows blind Command Injection, enabling an attacker without authentication to execute arbitrary operating system commands. This is achieved by injecting a vulnerable parameter in the PHP Web page /common/vam monitor sap.php.
Recommendations
For versions 4.15.0 through 4.29, consider restricting access to the /common/vam monitor sap.php endpoint until a fix is available, and avoid using the vulnerable parameter to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Selesta Visual Access Manager