vendor:
Admidio
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
RCE
CWE
Product Name: Admidio
Affected Version From: 4.2.10
Affected Version To: 4.2.10
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
Admidio v4.2.10 – Remote Code Execution (RCE)
The Admidio application version 4.2.10 is vulnerable to remote code execution (RCE). An attacker can exploit this vulnerability by uploading a malicious .phar file in the image upload section of the Announcements feature. The uploaded file can contain PHP code that executes system commands, allowing the attacker to execute arbitrary commands on the server. This can lead to unauthorized access, data theft, and further compromise of the system.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability yet. It is recommended to update to the latest version of the Admidio application when a patch becomes available. In the meantime, it is advised to restrict access to the Announcements feature and implement strict file upload validation to prevent the upload of malicious files.