SB2020090707 - Insecure handling of dangerous files in Concrete5



SB2020090707 - Insecure handling of dangerous files in Concrete5

Published: September 7, 2020

Security Bulletin ID SB2020090707
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restricitons bypass (CVE-ID: CVE-2020-24986)

The vulnerability allows a remote user to execute arbitrary PHP code.

The vulnerability exists due to application allows Concrete5 administrators to allow uploading of .php files to the server via File Manager. Once PHP files are allowed, a remote unprivileged user can upload and execute arbitrary PHP file on the system.


Remediation

Install update from vendor's website.