PT-2023-29763 · Unknown · Wpn-Xm Serverstack
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPN-XM Serverstack version 0.8.6
Description
A local file inclusion issue has been found, allowing an unauthenticated user to perform a local file inclusion via the "/tools/webinterface/index.php?page" parameter by sending a GET request. This could lead to the loading of a PHP file on the server, resulting in a critical webshell exploit.
Recommendations
For version 0.8.6, consider disabling the
index.php page in the /tools/webinterface/ directory until a patch is available. Restrict access to the page parameter in the affected API endpoint to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wpn-Xm Serverstack