Описание
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.
Ссылки
- Release Notes
- Patch
- Product
- VDB Entry
- VDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 7.14.2 (исключая)
cpe:2.3:a:filegator:filegator:*:*:*:*:*:*:*:*
EPSS
Процентиль: 2%
0.00112
Низкий
7.3 High
CVSS3
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 7.3
github
21 день назад
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.
EPSS
Процентиль: 2%
0.00112
Низкий
7.3 High
CVSS3
Дефекты
CWE-732