PT-2022-16561 · Ritecms · Ritecms
Published
2022-04-12
·
Updated
2022-04-20
·
CVE-2022-24248
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RiteCMS versions 3.1.0 and below
Description
The issue allows an authenticated attacker to delete any file in the web root, as well as other files on the server that the PHP process user has permissions to delete, via an arbitrary file deletion vulnerability using path traversal in the Admin Panel. This capability can be used to circumvent certain web server security mechanisms, such as deleting .htaccess files to deactivate security constraints.
Recommendations
For RiteCMS versions 3.1.0 and below, update to a version above 3.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the Admin Panel to minimize the risk of exploitation. Additionally, monitor server permissions and access controls to limit the potential damage from arbitrary file deletion.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ritecms