Описание
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.
Ссылки
- ExploitTechnical DescriptionThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- ExploitTechnical DescriptionThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.8.3 (включая)
cpe:2.3:a:wolfcms:wolf_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.14309
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.
EPSS
Процентиль: 94%
0.14309
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20