monstra-cms / monstra

THIS PROJECT IS NOT SUPPORTED ANYMORE! Check FLEXTYPE.ORG
http://flextype.org
MIT License
396 stars 123 forks source link

php code execution in snippets modul #455

Closed xiaohuihui1113 closed 5 years ago

xiaohuihui1113 commented 6 years ago

Hello sir, I have found a php code execution vulnerability in Monstra 3.0.4.Here I was able to execute PHP command.

visit: http://ip/monstra-3.0.4/admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics

In this page,input <?php phpinfo()?> example:

image

then visit:http://ip/monstra-3.0.4/index.php

image
Awilum commented 5 years ago

SNIPPETS CAN CREATE AND EDIT ADMIN AND TRUSTED USERS! SNIPPETS ALLOW TO USE HTML AND PHP CODE!