vendor:
BoxBilling
by:
zetc0de
7.2
CVSS
HIGH
Unrestricted File Upload
434
CWE
Product Name: BoxBilling
Affected Version From: <=4.22.1.5
Affected Version To: <=4.22.1.5
Patch Exists: YES
Related CWE: CVE-2022-3552
CPE: a:boxbilling:boxbilling
Platforms Tested: Windows 10
2022
BoxBilling<=4.22.1.5 – Remote Code Execution (RCE)
BoxBilling was vulnerable to Unrestricted File Upload. In order to exploit the vulnerability, an attacker must have a valid authenticated session as admin on the CMS. With at least 1 order of product an attacker can upload malicious file to hidden API endpoint that contain a webshell and get RCE
Mitigation:
Ensure that all file uploads are properly validated and restricted to only allow authorized users to upload files.