HIGH
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29
Published Feb 26, 2020
8.8
HIGHCVSS 3.1
EPSS 1.46%
Description
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to create and write XML files on the filesystem via /common/vam_editXml.php in the web interface. The vulnerable PHP page checks none of these: the parameter that identifies the file name to be created, the destination path, or the extension. Thus, an attacker can manipulate the file name to create any type of file within the filesystem with arbitrary content.
Affected products
No data.
- ≥ 4.15.0 · ≤ 4.29.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9576 Advisory
- https://www.seling.it/ x_refsource_MISCProduct
- https://www.seling.it/product/vam/ x_refsource_MISCProductVendor Advisory
- https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9576 | Advisory | |
| https://www.seling.it/ | x_refsource_MISCProduct | |
| https://www.seling.it/product/vam/ | x_refsource_MISCProductVendor Advisory | |
| https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 26, 2020
Updated Aug 5, 2024
Reserved Dec 26, 2019
Link CVE-2019-19988
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data