Vulnerability Description
Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Accela | Civic Platform Citizen Access Portal | - |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/665280Third Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/JLAD-ABMPVAThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/91765
- http://www.kb.cert.org/vuls/id/665280Third Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/JLAD-ABMPVAThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/91765
FAQ
What is CVE-2016-5661?
CVE-2016-5661 is a vulnerability with a CVSS score of 8.8 (HIGH). Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and f...
How severe is CVE-2016-5661?
CVE-2016-5661 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5661?
Check the references section above for vendor advisories and patch information. Affected products include: Accela Civic Platform Citizen Access Portal.