vendor:
Papoo CMS
by:
RedTeam Pentesting
5.5
CVSS
MEDIUM
Authenticated Arbitrary Code Execution
TBA
CWE
Product Name: Papoo CMS
Affected Version From: 3.7.2003
Affected Version To: 3.7.2003
Patch Exists: YES
Related CWE: TBA
CPE: papoo-cms
Platforms Tested:
2009
Papoo CMS: Authenticated Arbitrary Code Execution
The Papoo CMS allows authenticated users to upload GIF, JPG and PNG images if they have the "upload images" privilege, which is true for all default groups that can access the administrative interface. The CMS checks the uploaded images only for their header, but not for the file extension. It is therefore possible to upload images with the file extension ".php" and a valid image header. By embedding PHP code into the image (e.g. by using the GIF comments field), arbitrary code can be executed when requesting the image.
Mitigation:
Applying the vendor patch for version 3.7.3.