PT-2021-17100 · Eprints · Eprints
David R Newman
·
Published
2021-03-01
·
Updated
2021-03-04
·
CVE-2021-26703
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EPrints version 3.4.2
Description
The issue allows remote attackers to read arbitrary files and possibly execute commands by providing crafted JSON or XML input to the "cgi/ajax/phrase" API endpoint.
Recommendations
For EPrints version 3.4.2, consider restricting access to the cgi/ajax/phrase URI until a patch is available. As a temporary workaround, avoid using the cgi/ajax/phrase endpoint with JSON or XML input to minimize the risk of exploitation.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eprints