CVE-2017-3188 Information
Description
The dotCMS administration panel versions 3.7.1 and earlier \Push Publishing\ feature in Enterprise Pro is vulnerable to path traversal. When \Bundle\ tar.gz archives uploaded to the Push Publishing feature are decompressed the filenames of its contents are not properly checked allowing for writing files to arbitrary directories on the file system. These archives may be uploaded directly via the administrator panel or using the CSRF vulnerability (CVE-2017-3187). An unauthenticated remote attacker may perform actions with the dotCMS administrator panel with the same permissions of a victim user or execute arbitrary system commands with the permissions of the user running the dotCMS application.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Reference
http://www.securityfocus.com/bid/96616 https://doc.dotcms.com/security/SI-41 https://www.kb.cert.org/vuls/id/168699
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5
Share on: