PT-2021-11927 · Unknown · Bloofoxcms
Published
2021-06-04
·
Updated
2024-02-14
·
CVE-2020-36141
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
BloofoxCMS version 0.5.2.1
Description:
The issue allows for Unrestricted File Upload by bypassing MIME Type validation. This can be achieved by inserting 'image/jpeg' within the 'Content-Type' header, potentially allowing malicious files to be uploaded to the system.
Recommendations:
For BloofoxCMS version 0.5.2.1, consider validating the MIME Type of uploaded files more rigorously to prevent bypassing of the validation mechanism. As a temporary workaround, restrict the types of files that can be uploaded to mitigate the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bloofoxcms