PT-2021-11913 · Zenphoto · Zenphoto

Fgeeko

·

Published

2021-02-26

·

Updated

2024-08-04

·

CVE-2020-36079

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zenphoto versions 1.5.7 and earlier
Description: The issue allows for authenticated arbitrary file upload, leading to remote code execution. An attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI, potentially placing a .php file in the server's uploaded/ directory. It's noted that exploitation can only be performed by an admin, who already has significant possibilities to harm the site.
Recommendations: For versions 1.5.7 and earlier, consider disabling the uploader plugin or restricting access to the elFinder functionality until a patch is available. Additionally, restrict the ability to upload files, especially .php files, to the server's uploaded/ directory to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-36079

Affected Products

Zenphoto