PT-2020-12202 · Ossn · Ossn Open Source Social Network

Published

2020-03-30

·

Updated

2021-07-21

·

CVE-2020-10560

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Source Social Network (OSSN) versions through 5.3
Description An issue was discovered in Open Source Social Network (OSSN) where a user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn com.php and/or libraries/ossn.lib.upgrade.php.
Recommendations For Open Source Social Network (OSSN) versions through 5.3, consider disabling access to the components/OssnComments/ossn com.php and libraries/ossn.lib.upgrade.php files until a patch is available. Restrict access to the SiteKey to minimize the risk of exploitation. Avoid using user-controlled file paths to prevent potential abuse. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10560

Affected Products

Ossn Open Source Social Network