PT-2020-8650 · Fleetco · Fleetco Fleet Maintenance Management

Published

2020-03-02

·

Updated

2020-03-04

·

CVE-2018-19798

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Fleetco Fleet Maintenance Management (FMM) versions 1.2 and earlier
Description: The issue allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the "accidents add.php?submit=1" URI, as demonstrated by the value Images 1 field, which leads to remote command execution on the remote server. Any authenticated user can exploit this.
Recommendations: For versions 1.2 and earlier, consider disabling the file upload functionality in the accidents add.php endpoint until a patch is available. Restrict access to the accidents add.php?submit=1 URI to minimize the risk of exploitation. Avoid using the value Images 1 field in the affected endpoint until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19798

Affected Products

Fleetco Fleet Maintenance Management