PT-2020-15980 · Observium · Observium
Maciej Domański
·
Published
2020-09-25
·
Updated
2020-09-30
·
CVE-2020-25144
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Observium Professional, Enterprise & Community version 20.8.10631
Description
An issue in the software allows for directory traversal and local file inclusion due to unrestricted file loading with an inc.php extension. This can lead to Remote Code Execution via "API Endpoints" such as /apps/?app=../.
Recommendations
For version 20.8.10631, consider restricting access to the /apps/ endpoint to minimize the risk of exploitation. As a temporary workaround, restrict the possibility of loading any file with an inc.php extension until a patch is available.
Fix
Unrestricted File Upload
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Observium