PT-2020-12200 · Acontent · Acontent

Published

2020-03-16

·

Updated

2020-03-18

·

CVE-2020-10557

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AContent versions 1.4 and earlier
Description The issue allows a user to run commands on the server with a low-privileged account. It is caused by an arbitrary file upload vulnerability in the upload section of the file manager page via upload.php. The vulnerability can be exploited by uploading files with the .php7 extension, which bypasses file upload restrictions.
Recommendations For AContent versions 1.4 and earlier, as a temporary workaround, consider disabling the upload functionality in the file manager page until a patch is available. Restrict access to the upload.php file to minimize the risk of exploitation. Avoid using the file manager page for uploading files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10557

Affected Products

Acontent