PT-2022-10666 · Unknown · Nucleus Cms
Gsuhy-Lo
·
Published
2022-06-30
·
Updated
2022-07-09
·
CVE-2021-37770
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nucleus CMS version 3.71
Description
The issue allows an attacker to upload a malicious file by changing the upload path to a location without an Htaccess file. By uploading an Htaccess file with the content 'AddType application/x-httpd-php.jpg', an attacker can then upload a picture with a shell, which can be executed as PHP, enabling the attacker to execute commands and potentially take down website resources.
Recommendations
For Nucleus CMS version 3.71, consider disabling the file upload feature until a patch is available to prevent exploitation. Restrict access to the upload functionality to minimize the risk of malicious file uploads. Avoid using the upload feature to upload files with potentially executable content, such as images with embedded shells, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nucleus Cms