CVE-2018-19135 Information
Feb 14, 2021
cve
Description
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability one can automatically upload files (by default it allows html pdf xml zip and many other file types). A file can be accessed publicly under the /assets/files\ directory.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://github.com/ClipperCMS/ClipperCMS/issues/494 https://www.exploit-db.com/exploits/45839/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: