PT-2022-12197 · Xerte · Xerte
Rik Lutz
·
Published
2022-02-24
·
Updated
2022-07-12
·
CVE-2021-44664
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xerte versions through 3.9
Description
An Authenticated Remote Code Execution (RCE) issue exists in the website code/php/import/fileupload.php file. This is due to the ability to upload a maliciously crafted PHP file disguised as a language file, which bypasses the upload filters. Attackers can manipulate the file's destination by exploiting path traversal in the
mediapath variable.Recommendations
For versions through 3.9, consider disabling the file upload feature in the project interface until a patch is available. Restrict access to the
fileupload.php file to minimize the risk of exploitation. Avoid using the mediapath variable in the affected API endpoint until the issue is resolved.Exploit
Fix
Unrestricted File Upload
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xerte