vendor:
SofaWiki
by:
Ahmet Ümit BAYRAM
6.1
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: SofaWiki
Affected Version From: 3.9.2002
Affected Version To: 3.9.2002
Patch Exists: NO
Related CWE:
CPE: a:sofawiki:sofawiki:3.9.2
Platforms Tested: MacOS
2024
SofaWiki 3.9.2 – Remote Command Execution (RCE) (Authenticated)
The exploit allows an authenticated attacker to execute arbitrary commands on the target system. By uploading a PHP shell through the 'uploadedfile' parameter in the 'index.php' script, the attacker can run system commands via the 'cmd' parameter in the uploaded PHP shell.
Mitigation:
To mitigate this vulnerability, users should ensure they are using the latest patched version of SofaWiki. Additionally, restrict access to the application and avoid granting unnecessary permissions.