vendor:
Feehi CMS
by:
yuyudhn
5.4
CVSS
MEDIUM
Remote Code Execution (RCE)
78
CWE
Product Name: Feehi CMS
Affected Version From: 2.1.2001
Affected Version To: 2.1.2001
Patch Exists: YES
Related CWE: CVE-2022-34140
CPE: a:feehi:cms:2.1.1
Platforms Tested: Linux, Docker
2022
Feehi CMS 2.1.1 – Remote Code Execution (RCE) (Authenticated)
Feehi CMS 2.1.1 is vulnerable to Remote Code Execution (RCE) when an authenticated user uploads a malicious php script with jpg/png extension, and using Burp suite or any tamper data browser add ons, changes back the extension to php. The malicious script can be accessed at http://feehi-cms.local/uploads/setting/ad/[some_random_id].php
Mitigation:
Ensure that the application is up to date and patched with the latest security updates. Restrict access to the application to trusted users only.