PT-2021-22838 · Unknown · Php-Fusion

Kietna

·

Published

2021-10-11

·

Updated

2021-10-18

·

CVE-2021-40188

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPFusion version 9.03.110
Description The issue concerns an arbitrary file upload vulnerability. Specifically, the File Manager function in the admin panel does not filter all PHP extensions, such as .php, .php7, .phtml, .php5, etc. This allows an attacker to upload a malicious file and execute code on the server.
Recommendations For PHPFusion version 9.03.110, consider disabling the File Manager function in the admin panel until a patch is available to prevent the upload of malicious files. Restrict access to the admin panel to minimize the risk of exploitation. Avoid using the File Manager function to upload files with PHP extensions until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40188

Affected Products

Php-Fusion