PT-2022-12197 · Xerte · Xerte

Rik Lutz

·

Published

2022-02-24

·

Updated

2022-07-12

·

CVE-2021-44664

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xerte versions through 3.9
Description An Authenticated Remote Code Execution (RCE) issue exists in the website code/php/import/fileupload.php file. This is due to the ability to upload a maliciously crafted PHP file disguised as a language file, which bypasses the upload filters. Attackers can manipulate the file's destination by exploiting path traversal in the mediapath variable.
Recommendations For versions through 3.9, consider disabling the file upload feature in the project interface until a patch is available. Restrict access to the fileupload.php file to minimize the risk of exploitation. Avoid using the mediapath variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44664

Affected Products

Xerte