CVE-2018-20159 Information

Description

i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with the administrator role to upload arbitrary files to the main website directory. Exploitation involves uploading a .php\ file within a .zip\ file because a ZIP archive is accepted by /admin/?req=modules&action=add as a plugin and extracted to the main directory. In order for the .zip\ file to be accepted it must also contain a package.json file.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Reference

https://pentest.com.tr/exploits/i-doit-CMDB-1-11-2-Remote-Code-Execution.html https://www.exploit-db.com/exploits/45957

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.2

Share on: