Vulnerability Description
In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a .php file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackcat-Cms | Blackcat Cms | 1.2 |
References
- https://github.com/M4ple/vulnerability/blob/master/blackcat_cms_RCE/blackcat_cmsExploitIssue TrackingThird Party Advisory
- https://github.com/M4ple/vulnerability/blob/master/blackcat_cms_RCE/blackcat_cmsExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2017-13670?
CVE-2017-13670 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a .php file.
How severe is CVE-2017-13670?
CVE-2017-13670 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-13670?
Check the references section above for vendor advisories and patch information. Affected products include: Blackcat-Cms Blackcat Cms.