Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1mZjR3LThjaHItdzJ4Oc4AAgfG

SiteServer CMS RCE via unsafe file upload

A issue was discovered in SiteServer CMS prior to version 6.12. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.

Permalink: https://github.com/advisories/GHSA-ff4w-8chr-w2x9
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mZjR3LThjaHItdzJ4Oc4AAgfG
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: 8 months ago


CVSS Score: 7.2
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-ff4w-8chr-w2x9, CVE-2019-11401
References: Repository: https://github.com/siteserver/cms
Blast Radius: 1.0

Affected Packages

nuget:sscms
Dependent packages: 0
Dependent repositories: 0
Downloads: 59,817 total
Affected Version Ranges: < 6.12
Fixed in: 6.12
All affected versions:
All unaffected versions: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.12, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.2.0, 7.2.1, 7.2.2, 7.3.0