#VU20051 PHP file inclusion in Photo Gallery by 10Web - Mobile-Friendly Image Gallery

 

#VU20051 PHP file inclusion in Photo Gallery by 10Web - Mobile-Friendly Image Gallery

Published: August 12, 2019


Vulnerability identifier: #VU20051
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-98
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Photo Gallery by 10Web - Mobile-Friendly Image Gallery
Software vendor:
WebDorado Form Builder Team

Description

The vulnerability allows a remote authenticated user to include and execute arbitrary PHP files on the server.

The vulnerability exists due to incorrect input validation when including PHP files. A remote authenticated user can send a specially crafted HTTP request to the affected application, include and execute arbitrary PHP code on the system with privileges of the web server.


Remediation

Install update from vendor's website.

External links