vendor:
coppermine-gallery
by:
Mirabbas Ağalarov
6.1
CVSS
HIGH
RCE
CWE
Product Name: coppermine-gallery
Affected Version From: v1.6.25
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:coppermine-gallery:coppermine-gallery:1.6.25
Platforms Tested: Linux
2023
coppermine-gallery 1.6.25 RCE
The coppermine-gallery version 1.6.25 is vulnerable to Remote Code Execution (RCE) attack. By uploading a specially crafted zip file containing a PHP file with malicious code, an attacker can execute arbitrary commands on the server. This can lead to unauthorized access, data leakage, and potential compromise of the entire system.
Mitigation:
Update to a patched version of coppermine-gallery (v1.6.26 or later) that addresses this vulnerability. Ensure that file uploads are properly validated and sanitized. Regularly monitor for any unauthorized file uploads or suspicious activities on the server.