vendor:
Monstra CMS
by:
Wenming Jiang
6.5
CVSS
MEDIUM
Insecure Permissions
269
CWE
Product Name: Monstra CMS
Affected Version From: 3.0.4
Affected Version To: 3.0.4
Patch Exists: NO
Related CWE: CVE-2018-9038
CPE: a:monstra_cms:monstra:3.0.4
Platforms Tested: macOS 10.12.6, PHP 5.6, Apache 2.2.29
2018
Monstra CMS 3.0.4 allows remote attackers to delete folder via a GET request
Monstra CMS 3.0.4 allows remote attackers to delete folder via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
Mitigation:
Strictly filter the delete_dir parameter and replace './' with '_/'