PT-2022-3952 · Unknown · Ossn Open Source Social Network
Published
2022-07-25
·
Updated
2024-08-03
·
CVE-2022-34965
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Open Source Social Network version 6.3 LTS
Description
The issue is related to an arbitrary file upload vulnerability in the /ossn/administrator/com installer component. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note that the project owner believes this behavior is intended, as it only allows authenticated admins to upload files.
Recommendations
For version 6.3 LTS, consider restricting access to the /ossn/administrator/com installer component to minimize the risk of exploitation. As a temporary workaround, consider disabling the file upload functionality in this component until a patch is available. Restrict access to the vulnerable component to only authenticated admins to reduce the risk of arbitrary code execution.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ossn Open Source Social Network