quickapps / cms

Modular CMS powered by CakePHP
GNU General Public License v3.0
164 stars 69 forks source link

[File upload vulnerability] CVE-2019-19576 is exist in the code! #202

Open seongil-wi opened 2 years ago

seongil-wi commented 2 years ago

Hi,

Our research team in KAIST WSP Lab found a known file upload vulnerability in quickapps Please inspect this spot.

The following known vulnerabilities exist in this code: CVE-2019-19576 The file extension filter is a blacklist, so any time a new extension is introduced (in this case phar), or any has been missed, a PHP file can be uploaded.

Thanks!