PT-2021-21311 · Artica · Artica Pandora Fms
K4M1Ll0
+1
·
Published
2021-11-03
·
Updated
2021-11-05
·
CVE-2021-36697
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Artica Pandora FMS versions <=755
Description
The issue allows an admin account to overwrite the .htaccess file using the File Manager component. A new .htaccess file can be created with a Rewrite Rule and a type definition, enabling the upload of a normal PHP file with the newly defined "file type". This PHP file can then be executed via an HTTP request.
Recommendations
For Artica Pandora FMS versions <=755, consider restricting access to the File Manager component to prevent overwriting the .htaccess file until a fix is available. As a temporary workaround, monitor and limit the creation of new .htaccess files and the upload of PHP files to minimize the risk of exploitation.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artica Pandora Fms