vendor:
Chupix CMS
by:
7.5
CVSS
HIGH
Remote File Download
22
CWE
Product Name: Chupix CMS
Affected Version From: 2000.2.3
Affected Version To: 2000.2.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Chupix CMS 0.2.3 (download.php) Remote File Download Vulnerability
The Chupix CMS version 0.2.3 is vulnerable to remote file download. The vulnerability exists in the 'download.php' script. An attacker can exploit this vulnerability by manipulating the 'fichier' parameter in the URL to download arbitrary files from the server. This can lead to unauthorized access to sensitive files and information.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a newer version of Chupix CMS that includes a fix for this issue. Additionally, ensure that input validation and sanitization is implemented to prevent manipulation of the 'fichier' parameter.