PT-2020-7793 · Unknown+1 · Collabtive+1
Published
2020-02-17
·
Updated
2022-01-01
·
CVE-2015-0258
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Collabtive versions prior to 2.1
Description:
The issue is related to multiple incomplete blacklist vulnerabilities in the avatar upload functionality. This allows remote authenticated users to execute arbitrary code by uploading files with specific extensions, such as
.php3, .php4, .php5, or .phtml.Recommendations:
For versions prior to 2.1, update to version 2.1 or later to resolve the issue. As a temporary workaround, consider restricting the file types that can be uploaded through the avatar upload functionality to prevent exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Collabtive
Ubuntu