PT-2024-21400 · Kirby Cms · Kirby Cms
Plynatwara
·
Published
2024-02-21
·
Updated
2024-08-01
·
CVE-2024-26483
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kirby CMS version 4.1.0
Description
The issue is related to an arbitrary file upload vulnerability in the Profile Image module, allowing attackers to execute arbitrary code via a crafted PDF file. This vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. The attack requires user interaction by another user or visitor and cannot be automated. The vulnerability can be abused to upload unexpected file types, such as PDFs, which could make it possible to perform cross-site scripting (XSS) attacks.
Recommendations
For Kirby CMS version 4.1.0, update to version 4.1.1 or a later version to fix the vulnerability. This update includes validations that prevent any files that don't have an image file extension or MIME type from being uploaded as a user avatar. As a temporary workaround, consider restricting access to the Profile Image module to minimize the risk of exploitation. Avoid using the module to upload files other than images until the issue is resolved.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kirby Cms