LibrettoCMS File Manager Arbitrary File Upload
Vulnerability Description
An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions and subsequently rename them to executable .php scripts. This enables remote code execution on the server without authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10054
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- CWH
- sinn3r
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/libretto_upload_exec.rb
- https://www.exploit-db.com/exploits/26213
- https://www.exploit-db.com/exploits/26421
- https://sourceforge.net/projects/librettocms/
- https://www.vulncheck.com/advisories/librettocms-file-manager-arbitrary-file-upload
Affected Vendor
LibrettoCMS
View all reports →