vendor:
Content Management System (CMS)
by:
alt3kx
9.8
CVSS
CRITICAL
Remote Code Execution
284
CWE
Product Name: Content Management System (CMS)
Affected Version From: 9.20 SP2
Affected Version To: 9.20 SP2
Patch Exists: YES
Related CWE: CVE-2018-12596
CPE: a:ektron:ektron_cms:9.20_sp2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2018
Ektron CMS 9.20 SP2 Remote Code Execution Vulnerability
Ektron CMS 9.20 SP2 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins). Pre-requisites: curl command deployed (Windows or Linux) and Burpsuite Free/Pro deployed or any other WebProxy to catch/send GET request.
Mitigation:
Ensure that the "activateuser.aspx" page is not accessible from outside the local network.