#VU27525 Permissions, Privileges, and Access Controls in MonoX - CVE-2020-12470

 

#VU27525 Permissions, Privileges, and Access Controls in MonoX - CVE-2020-12470

Published: May 5, 2020


Vulnerability identifier: #VU27525
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-12470
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
MonoX
Software vendor:
Mono

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in the "ctlUpload_radUploadfile0" parameter in "MonoX.MonoSoftware.MonoX.Admin.PageManagerPageTemplates" file. A remote administrator can modify ASPX templates for the entire site, gain elevated privileges and execute arbitrary code.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links