CVE-2018-10795
Last modified
CVE-2018-10795 is a vulnerability of currently unknown severity. Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Liferay Portal | <= 6.2.5 |
References
- https://cxsecurity.com/issue/WLB-2018050029Exploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2018050029Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10795?
How severe is CVE-2018-10795?
How do I fix CVE-2018-10795?
Are you affected by CVE-2018-10795?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
