vendor:
eLabFTW
by:
liquidsky (JMcPeters)
7.5
CVSS
HIGH
Arbitrary File Upload / RCE
264
CWE
Product Name: eLabFTW
Affected Version From: 1.8.5
Affected Version To: 1.8.5
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux / PHP Version 7.0.33 / Default installation (Softaculous)
2019
eLabFTW 1.8.5 ‘EntityController’ Arbitrary File Upload / RCE
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
Mitigation:
Ensure that the application is properly configured to prevent arbitrary file uploads.