Lucene search

K
githubGitHub Advisory DatabaseGHSA-FPPH-MQC8-H6Q5
HistoryDec 21, 2023 - 6:30 p.m.

Withdrawn Advisory: Unrestricted File Upload affecting automad

2023-12-2118:30:23
CWE-79
CWE-434
GitHub Advisory Database
github.com
7
automad
file upload
vulnerability
content type handler
exploit
unrestricted upload
remote attack

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

MULTIPLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:M/C:P/I:P/A:P

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

20.0%

Withdrawn Advisory

This advisory has been withdrawn because JavaScript execution is the intended functionality of automad. This link is maintained to preserve external references.

Original Description

A vulnerability was found in automad up to 1.10.9. This affects the function upload of the file FileCollectionController.php of the component Content Type Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely and an exploit has been disclosed publicly.

Affected configurations

Vulners
Node
automadautomadRange1.10.9
VendorProductVersionCPE
automadautomad*cpe:2.3:a:automad:automad:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

MULTIPLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:M/C:P/I:P/A:P

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

20.0%

Related for GHSA-FPPH-MQC8-H6Q5