vendor:
i-doit Open
by:
Özkan Mustafa Akkuş (AkkuS)
9.8
CVSS
HIGH
Remote Code Execution
264
CWE
Product Name: i-doit Open
Affected Version From: 1.11.2
Affected Version To: 1.11.2
Patch Exists: NO
Related CWE: N/A
CPE: a:i-doit:i-doit_open
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: XAMPP for Linux 5.6.38-0
2018
i-doit CMDB 1.11.2 – Remote Code Execution
This application has an upload feature that allows an authenticated user with administrator roles to upload arbitrary files to the main website directory. An attacker can upload a .zip file containing a malicious .php file, which can then be executed remotely.
Mitigation:
Ensure that the application is configured to only accept files with specific extensions and that the application is configured to only allow authenticated users with the appropriate privileges to upload files.