vendor:
ChurchRota
by:
Rob McCarthy
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ChurchRota
Affected Version From: 2.6.4
Affected Version To: 2.6.4
Patch Exists: YES
Related CWE: N/A
CPE: 2.6.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2021
ChurchRota 2.6.4 – RCE (Authenticated)
Church Rota version 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file. The application is written primarily with PHP so we use PHP in our PoC
Mitigation:
Ensure that the application is running the latest version of ChurchRota and that all users have the least privilege necessary to perform their job functions.