vendor:
RiteCMS
by:
faisalfs10x
7.5
CVSS
HIGH
Arbitrary File Overwrite
264
CWE
Product Name: RiteCMS
Affected Version From: 3.1.2000
Affected Version To: 3.1.2000
Patch Exists: NO
Related CWE:
CPE: a:ritecms:ritecms:3.1.0
Platforms Tested: Windows 10, Ubuntu 18, XAMPP
2021
RiteCMS 3.1.0 – Arbitrary File Overwrite (Authenticated)
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to write). Furthermore, an attacker might leverage the capability of arbitrary file overwrite to modify existing file such as /etc/passwd or /etc/shadow if the current PHP process user is run as root.
Mitigation:
Ensure that the web server is configured to deny access to any files that are not explicitly required for the application to function. Additionally, ensure that the web server is configured to deny access to any files that are not explicitly required for the application to function.