e107 CMS
cpe:2.3:a:e107:e107_cms:*:*:*:*:*:*:*
- 3.2.1
A file upload vulnerability has been identified in e107 CMS version 3.2.1. This vulnerability allows authenticated administrative users to bypass upload restrictions and execute PHP files. By manipulating the upload URL parameter, attackers can upload malicious PHP files to parent directories. The vulnerability is exploited through the Media Manager import feature, enabling remote code execution.
Exploitation of this vulnerability leads to remote code execution on the server.
To reproduce this vulnerability, an authenticated admin user can upload a file via the Media Manager. By selecting a file type that is normally restricted, such as an SVG or PHP file, and using the import feature to upload it from a remote location, the file can be executed on the server. For example, uploading a PHP file named 'cmd.php' and then accessing it directly would demonstrate the successful execution of the uploaded code.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.