Directory traversal in Bitrix Site Manager - #VU6146

 

Directory traversal in Bitrix Site Manager - #VU6146

Published: March 21, 2017


Vulnerability identifier: #VU6146
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:L]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files on vulnerable system.

The vulnerability exists in "makeFileArrayFromArray()" function in "/bitrix/modules/advertising/classes/general/advertising.php" when processing file uploads. A remote authenticated attacker with access to "Advertising and banners" module can upload arbitrary file on the target system with specially crafted filename, containing directory traversal sequences (e.g. ../) and overwrite certain files on vulnerable system outside the web root directory.



Affected software

Bitrix Site Manager

Remediation

Update "Advertising and banners" module to the latest version 17.0.0.


External References

Related Security Bulletins