PT-2020-12204 · Devome · Devome Grr

Published

2020-03-13

·

Updated

2020-03-18

·

CVE-2020-10562

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DEVOME GRR versions prior to 3.4.1c
Description An issue was discovered in the handling of file uploads by the admin edit room.php script. This issue affects the software's ability to properly manage file uploads, potentially leading to security concerns.
Recommendations For versions prior to 3.4.1c, update to version 3.4.1c or later to resolve the issue. As a temporary workaround, consider restricting access to the admin edit room.php script to minimize the risk of exploitation. Avoid using the file upload functionality in the affected script until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10562

Affected Products

Devome Grr