CVE-2018-12941 Information
Description
This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command at the end of the \cacheDir\ path and following usage of the \Clear Cache\ functionality. This allows an authenticated attacker with permission to the Settings functionality to inject arbitrary system commands within the application by manipulating the \Cache directory\ path. An attacker can use it to perform malicious tasks such as to extract change or delete sensitive information or run system commands on the underlying operating system.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://sourceforge.net/p/seeddms/code/ci/seeddms-5.1.x/tree/CHANGELOG https://www.contextis.com/resources/advisories/cve-2018-12941
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: