PT-2024-10836 · Unknown · Cyberaz0R Webrat
Cyberaz0R
·
Published
2024-03-24
·
Updated
2024-08-04
·
CVE-2020-36825
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
cyberaz0r WebRAT up to 20191222
Description
A critical issue affects the function
download file of the file Server/api.php. The manipulation of the argument name leads to unrestricted upload. The attack can be initiated remotely. The real existence of this issue is still doubted at the moment.Recommendations
Apply a patch to fix this issue, specifically the patch identified as 0c394a795b9c10c07085361e6fcea286ee793701. As a temporary workaround, consider restricting access to the
download file function in the Server/api.php file until a patch is applied. Avoid using the name argument in the affected API endpoint until the issue is resolved.Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyberaz0R Webrat