vendor:
Zeta Producer Desktop CMS
by:
P. Morimoto (Office Bangkok)
5.5
CVSS
MEDIUM
Remote Code Execution & Local File Disclosure
78
CWE
Product Name: Zeta Producer Desktop CMS
Affected Version From: <=14.2.0
Affected Version To: >=14.2.1
Patch Exists: YES
Related CWE: CVE-2018-13981, CVE-2018-13980
CPE: a:zeta-producer:zeta_producer_desktop_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Remote Code Execution & Local File Disclosure
The email contact functionality of the widget "formmailer" can upload files to the server but if the user uploads a PHP script with a .php extension then the server will rename it to .phps to prevent PHP code exec. However, the server does not check the content of the file and if the uploaded file contains PHP code, the code will be executed. An attacker can also send a crafted request to the server and the server will respond with the content of the requested file.
Mitigation:
The vendor provides a patched version which should be installed immediately. Users of the product also need to verify that the affected widgets are updated in the corresponding website project! It could be necessary to rebuild the whole project or copy the new widgets to the website projects. For further information consult the vendor. Furthermore, an in-depth security analysis is highly advised, as the software may be affected from further security issues.