admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin permission. We think it's pretty rare for an administrator to exploit a bug on his/her own site to own his/her own site.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:40:16.048Z

Reserved: 2019-04-08T00:00:00

Link: CVE-2019-11021

cve-icon Vulnrichment

Updated: 2024-08-04T22:40:16.048Z

cve-icon NVD

Status : Modified

Published: 2019-10-24T16:15:20.047

Modified: 2024-11-21T04:20:22.730

Link: CVE-2019-11021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses