CVE-2020-27385
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file> in the input field of the FileEditor. In FlexDotnetCMS before v1.5.8, it is also possible to access files by specifying the full path (e.g., C:\<file>). The files can then be edited via the FileEditor.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- flexdotnetcms project/flexdotnetcms
- Source
- cve@mitre.org
References
- https://blog.vonahi.io/whats-in-a-re-name/Exploit, Third Party Advisory
- https://github.com/MacdonaldRobinson/FlexDotnetCMS/releases/tag/v1.5.11Release Notes, Third Party Advisory
- https://blog.vonahi.io/whats-in-a-re-name/Exploit, Third Party Advisory
- https://github.com/MacdonaldRobinson/FlexDotnetCMS/releases/tag/v1.5.11Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.