vendor:
RiteCMS
by:
faisalfs10x
7.5
CVSS
HIGH
Arbitrary File Deletion
22
CWE
Product Name: RiteCMS
Affected Version From: 3.1.2000
Affected Version To: 3.1.2000
Patch Exists: NO
Related CWE:
CPE: a:ritecms:ritecms:3.1.0
Platforms Tested: Windows 10, Ubuntu 18, XAMPP
2021
RiteCMS 3.1.0 – Arbitrary File Deletion (Authenticated)
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to delete). Furthermore, an attacker might leverage the capability of arbitrary file deletion to circumvent certain webserver security mechanisms such as deleting .htaccess file that would deactivate those security constraints.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a version higher than 3.1.0. Additionally, ensure proper access controls are in place to restrict unauthorized access to the Admin Panel.