PT-2020-13855 · Ozeki · Ozeki Ng Sms Gateway
Drunkenshells
·
Published
2020-09-22
·
Updated
2020-09-26
·
CVE-2020-14031
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ozeki NG SMS Gateway versions through 4.17.6
Description
An issue was discovered in the outbox functionality of the TXT File module, allowing it to delete most files in a folder. Since the product typically runs as NT AUTHORITYSYSTEM, the only files that will not be deleted are those currently being run by the system and/or files with special security attributes.
Recommendations
For Ozeki NG SMS Gateway versions through 4.17.6, consider restricting access to the outbox functionality of the TXT File module to prevent unauthorized file deletion until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ozeki Ng Sms Gateway