vendor:
Wallos
by:
sml
7.1
CVSS
HIGH
Remote Code Execution (RCE)
434
CWE
Product Name: Wallos
Affected Version From: Version 1.0
Affected Version To: Version 1.11.2
Patch Exists: NO
Related CWE: CVE-2024-XXXXX
CPE: a:ellite:wallos
Platforms Tested: Debian 12
2024
Wallos – File Upload Remote Code Execution (Authenticated)
Wallos, a subscription management system, is vulnerable to a file upload RCE exploit. By manipulating the file upload functionality, an authenticated attacker can upload a malicious .php file containing a web shell. This allows them to execute arbitrary commands on the target system.
Mitigation:
To mitigate this vulnerability, ensure that file uploads are properly validated and restricted to specific file types. Implement input validation to prevent the upload of executable files. Regularly update the software to patched versions.