PT-2020-12202 · Ossn · Ossn Open Source Social Network
Published
2020-03-30
·
Updated
2021-07-21
·
CVE-2020-10560
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open Source Social Network (OSSN) versions through 5.3
Description
An issue was discovered in Open Source Social Network (OSSN) where a user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn com.php and/or libraries/ossn.lib.upgrade.php.
Recommendations
For Open Source Social Network (OSSN) versions through 5.3, consider disabling access to the components/OssnComments/ossn com.php and libraries/ossn.lib.upgrade.php files until a patch is available. Restrict access to the SiteKey to minimize the risk of exploitation. Avoid using user-controlled file paths to prevent potential abuse. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ossn Open Source Social Network