vendor:
PerfexCRM
by:
Ahmad Mahfouz
9.8
CVSS
CRITICAL
Unrestricted File Upload
434
CWE
Product Name: PerfexCRM
Affected Version From: 1.9.7
Affected Version To: 1.9.7
Patch Exists: Yes
Related CWE: CVE-2017-17976
CPE: a:perfexcrm:perfexcrm:1.9.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
PerfexCRM 1.9.7 – Unrestricted php5 File upload
PerfexCRM 1.9.7 is prone to unrestricted file upload that lead to system take over by misconfigured elfinder plugin. Bypassing the misconfigured file upload with file .php5 and bypassing the file content restriction by adding TEXT line to represent mime type text.
Mitigation:
Ensure that the elfinder plugin is properly configured and that all file uploads are properly validated.