vendor:
WSO2 API Manager Carbon Interface
by:
raki ben hamouda
8.5
CVSS
HIGH
Arbitrary File Delete
N/A
CWE
Product Name: WSO2 API Manager Carbon Interface
Affected Version From: WSO2 API Manager Carbon Interface
Affected Version To: WSO2 API Manager Carbon Interface
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Remote
2020
WSO2 API Manager(Delete Extension) Arbitrary File Delete(Path traversal )
A remote Arbitrary file delete vulnerability has been discovered in the official WSO2 API Manager Carbon UI product. The security vulnerability allows a remote attacker with low privileges to perform authenticated application requests and to delete arbitrary System files. The vulnerability is located in the `/carbon/extensions/deleteExtension-ajaxprocessor.jsp` modules and the `extensionName` parameter of the extension we want to delete. Remote attackers are able to delete arbitrary files as configuration files, database(.db) files via authenticated POST method requests with a crafted String arbitrary traversal files names in "extensionName".
Mitigation:
Update to the latest version of WSO2 API Manager Carbon UI product.