A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/upload/drop of the component File Upload. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6099 | A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/upload/drop of the component File Upload. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component. |
Github GHSA |
GHSA-mwh6-g9wx-xcx3 | Unrestricted Upload of File with Dangerous Type in Elefant CMS |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-15T14:19:12.837Z
Reserved: 2022-06-18T00:00:00.000Z
Link: CVE-2017-20063
Updated: 2024-08-05T21:45:25.419Z
Status : Modified
Published: 2022-06-20T05:15:07.877
Modified: 2024-11-21T03:22:33.183
Link: CVE-2017-20063
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA