vendor:
Verot 2.0.3 PHP class
by:
Jinny Ramsmark
9.8
CVSS
CRITICAL
Remote Code Execution
434
CWE
Product Name: Verot 2.0.3 PHP class
Affected Version From: <=2.0.3
Affected Version To: <=2.0.3
Patch Exists: YES
Related CWE: CVE-2019-19576
CPE: a:verot:class.upload.php
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 19.10, PHP 7.3, Apache/2.4.41
2019
Verot 2.0.3 – Remote Code Execution
This exploit allows an attacker to execute arbitrary code on the vulnerable system by uploading a malicious image file. The vulnerability exists in the Verot 2.0.3 PHP class, which is used to upload files. The vulnerability is due to insufficient validation of the uploaded file, allowing an attacker to upload a malicious image file containing PHP code, which is then executed on the server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of the Verot 2.0.3 PHP class.