PT-2020-16210 · Typesetter · Typesetter Cms
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Typesetter CMS versions 5.x through 5.1
Description
The issue allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. This behavior contradicts the security policy, and the vendor is fixing it for version 5.2, despite considering admins trustworthy.
Recommendations
For versions 5.x through 5.1, consider disabling the upload functionality for ZIP archives containing .php files until a patch is available.
As a temporary workaround, restrict access to the upload feature to minimize the risk of exploitation.
Avoid using the upload feature for ZIP archives until the issue is resolved in version 5.2.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typesetter Cms