vendor:
CuteNews
by:
Vigov5 - SunCSR Team
8.8
CVSS
HIGH
Authenticated Arbitrary File Upload
434
CWE
Product Name: CuteNews
Affected Version From: 2.1.2
Affected Version To: 2.1.2
Patch Exists: NO
Related CWE: N/A
CPE: 2.1.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04 / Kali Linux
2020
CuteNews 2.1.2 – Authenticated Arbitrary File Upload
In the 'Media Manager' area, Users with low privileges (Editor) can bypass file upload restrictions, resulting in arbitrary command execution.
Mitigation:
Restrict access to the 'Media Manager' area to users with higher privileges.