Webshell Upload Vulnerability in Codiad by Codiad Team
CVE-2017-1000125

7.5HIGH

Key Information:

Vendor

Codiad

Status
Vendor
CVE Published:
17 November 2017

What is CVE-2017-1000125?

Codiad's full version has a security flaw that allows attackers to write arbitrary data to the configuration file during installation. This oversight can be exploited to upload a malicious webshell, potentially compromising the server's integrity and security. Immediate attention and remedial measures are essential to safeguard affected systems.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.