PT-2024-10836 · Unknown · Cyberaz0R Webrat

Cyberaz0R

·

Published

2024-03-24

·

Updated

2024-08-04

·

CVE-2020-36825

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cyberaz0r WebRAT up to 20191222
Description A critical issue affects the function download file of the file Server/api.php. The manipulation of the argument name leads to unrestricted upload. The attack can be initiated remotely. The real existence of this issue is still doubted at the moment.
Recommendations Apply a patch to fix this issue, specifically the patch identified as 0c394a795b9c10c07085361e6fcea286ee793701. As a temporary workaround, consider restricting access to the download file function in the Server/api.php file until a patch is applied. Avoid using the name argument in the affected API endpoint until the issue is resolved.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-36825

Affected Products

Cyberaz0R Webrat