PT-2020-8650 · Fleetco · Fleetco Fleet Maintenance Management
Published
2020-03-02
·
Updated
2020-03-04
·
CVE-2018-19798
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Fleetco Fleet Maintenance Management (FMM) versions 1.2 and earlier
Description:
The issue allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the "accidents add.php?submit=1" URI, as demonstrated by the
value Images 1 field, which leads to remote command execution on the remote server. Any authenticated user can exploit this.Recommendations:
For versions 1.2 and earlier, consider disabling the file upload functionality in the accidents add.php endpoint until a patch is available. Restrict access to the accidents add.php?submit=1 URI to minimize the risk of exploitation. Avoid using the
value Images 1 field in the affected endpoint until the issue is resolved.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fleetco Fleet Maintenance Management