PT-2020-16065 · Pligg · Pligg

Jenaye

·

Published

2020-09-13

·

Updated

2020-09-17

·

CVE-2020-25287

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pligg version 2.0.3
Description The issue allows remote authenticated users to execute arbitrary commands. This is possible because the template editor can edit any file. For example, an attacker can send a request to admin/admin editor.php with parameters like the file=..%2Findex.php and open=Open to execute arbitrary commands.
Recommendations For Pligg version 2.0.3, restrict access to the template editor to prevent unauthorized file edits. As a temporary workaround, consider disabling the template editor until a patch is available.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25287

Affected Products

Pligg