monstra-cms / monstra

THIS PROJECT IS NOT SUPPORTED ANYMORE! Check FLEXTYPE.ORG
http://flextype.org
MIT License
396 stars 123 forks source link

RCE (Remote Code Execution via Theme Blog Monstra version 3.0.4) #470

Closed r0ck3t1973 closed 2 years ago

r0ck3t1973 commented 3 years ago

Describe the bug An attacker could insert any executable code through php via Theme Blog to execution command in the server

To Reproduce

  1. Log into the panel.
  2. Go to "/monstra-3.0.4/admin/index.php?id=themes&action=edit_template&filename=blog"
  3. Click edit Blog
  4. Insert payload easy-simple-php-webshell.php
  5. Reload page review code excution

image

image