PT-2020-11978 · Responsive Filemanager · Responsive Filemanager
Bl4Ckh4Ck5
·
Published
2020-03-06
·
Updated
2020-03-09
·
CVE-2020-10212
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Responsive FileManager versions 9.13.4 through 9.14.0
Description
The issue allows for Server-Side Request Forgery (SSRF) via the
url parameter in the upload.php file. This is due to mishandled file-extension blocking and the possibility of a DNS hostname resolving to an internal IP address. For example, adding a .ico filename to the PATH INFO can lead to a successful SSRF attempt. An attacker could also create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning.Recommendations
For Responsive FileManager versions 9.13.4 through 9.14.0, consider disabling the upload.php file or restricting access to it until a proper fix is applied. Avoid using the
url parameter in the upload.php file to minimize the risk of exploitation. As a temporary workaround, restrict the handling of file extensions and DNS hostnames to prevent SSRF attempts.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Responsive Filemanager