PT-2024-3328 · Maccms · Maccms

Ally Petitt

·

Published

2024-04-12

·

Updated

2024-08-01

·

CVE-2023-45503

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Macs CMS version 1.1.4f
Description The issue is related to a lack of protection against SQL injection attacks when handling certain parameters, including resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, allowComment, and addComment. This can allow a remote attacker to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information by sending specially crafted requests to the affected endpoints, such as "/resetPassword" or "/saveUser".
Recommendations For Macs CMS version 1.1.4f, as a temporary workaround, consider disabling the resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, allowComment, addComment, and saveUser functions until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation. Avoid using the parameters resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, allowComment, addComment, and saveUser in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-03574
CVE-2023-45503

Affected Products

Maccms