Vulnerability Description
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during processing of a Remote Content page type. This unserialization can be used to trigger the inclusion of arbitrary files on the filesystem (local file inclusion), and results in remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squiz | Matrix | >= 5.5.0.0, < 5.5.0.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/155671/Squiz-Matrix-CMS-5.5.x.x-Code-ExecutExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Dec/34ExploitMailing ListThird Party Advisory
- https://matrix.squiz.net/releases/5.5/5.5.3.3Release Notes
- https://zxsecurity.co.nz/wp-content/uploads/2019/12/ZX%20Security%20Advisory%20-ExploitThird Party Advisory
- http://packetstormsecurity.com/files/155671/Squiz-Matrix-CMS-5.5.x.x-Code-ExecutExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Dec/34ExploitMailing ListThird Party Advisory
- https://matrix.squiz.net/releases/5.5/5.5.3.3Release Notes
- https://zxsecurity.co.nz/wp-content/uploads/2019/12/ZX%20Security%20Advisory%20-ExploitThird Party Advisory
FAQ
What is CVE-2019-19373?
CVE-2019-19373 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a P...
How severe is CVE-2019-19373?
CVE-2019-19373 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19373?
Check the references section above for vendor advisories and patch information. Affected products include: Squiz Matrix.