Remote Code Execution Vulnerability in i-doit Open by Synetics
CVE-2018-20159
Key Information:
Badges
What is CVE-2018-20159?
The i-doit Open version 1.11.2 allows for remote code execution due to inappropriate handling of ZIP archives. An authenticated user with administrator privileges can upload a specially crafted ZIP file that contains an executable PHP file. The vulnerability arises from the upload feature that permits ZIP archives to be extracted to the main website directory. To exploit this vulnerability, the ZIP file must include a package.json file along with the PHP file to be processed correctly. This oversight poses significant security risks, as it can allow attackers to execute arbitrary code on the server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability Reserved
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
