PT-2021-11913 · Zenphoto · Zenphoto
Fgeeko
·
Published
2021-02-26
·
Updated
2024-08-04
·
CVE-2020-36079
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Zenphoto versions 1.5.7 and earlier
Description:
The issue allows for authenticated arbitrary file upload, leading to remote code execution. An attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI, potentially placing a .php file in the server's uploaded/ directory. It's noted that exploitation can only be performed by an admin, who already has significant possibilities to harm the site.
Recommendations:
For versions 1.5.7 and earlier, consider disabling the uploader plugin or restricting access to the elFinder functionality until a patch is available. Additionally, restrict the ability to upload files, especially .php files, to the server's uploaded/ directory to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenphoto