CVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax="c;id"' line to execute the id command.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 16.13% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- enalean/tuleap · phpwiki project/phpwiki
- Source
- cve@mitre.org
References
- https://github.com/xdrr/vulnerability-research/blob/master/webapp/tuleap/2017.04.tuleap-auth-ci.mdExploit, Third Party Advisory
- https://tuleap.net/file/shownotes.php?release_id=137#/linked-artifactsRelease Notes, Vendor Advisory
- https://tuleap.net/plugins/tracker/?aid=10159Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/41953/Third Party Advisory, VDB Entry
- https://github.com/xdrr/vulnerability-research/blob/master/webapp/tuleap/2017.04.tuleap-auth-ci.mdExploit, Third Party Advisory
- https://tuleap.net/file/shownotes.php?release_id=137#/linked-artifactsRelease Notes, Vendor Advisory
- https://tuleap.net/plugins/tracker/?aid=10159Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/41953/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.