Advisories

e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override

Go Back
severity
high
date
Affecting
  • e107 CMS 3.2.1

CWE
  • CWE-434 Unrestricted Upload of File with Dangerous Type
CVSS
8.7
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Hubert Wojciechowski
Description
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.