PT-2022-16774 · Sentcms · Sentcms
Hanayuzu
·
Published
2022-03-10
·
Updated
2022-03-16
·
CVE-2022-24651
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
sentcms versions 4.0.x
Description
The issue allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through the "/user/upload/upload" API endpoint.
Recommendations
For sentcms versions 4.0.x, consider disabling the file upload feature or restricting access to the "/user/upload/upload" API endpoint until a patch is available.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentcms