Remote File Upload Vulnerability in BlackCat CMS by M4ple
CVE-2017-13670

6.5MEDIUM

Key Information:

Vendor
CVE Published:
31 August 2017

What is CVE-2017-13670?

In BlackCat CMS version 1.2, a vulnerability exists that allows remote authenticated users to upload arbitrary files through the media upload functionality located in backend/media/ajax_upload.php. This issue can potentially be exploited by uploading a ZIP archive that contains a PHP file, leading to serious security risks, including unauthorized execution of code on the server.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-13670 : Remote File Upload Vulnerability in BlackCat CMS by M4ple