CVE Vulnerabilities

CVE-2018-18924

Incomplete Cleanup

Published: Nov 04, 2018 | Modified: Aug 24, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with #exec cmd because rejected files remain on the server, with predictable filenames, after a This file is not a valid image error message.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Projeqtor Projeqtor * 7.2.5 (including)

Potential Mitigations

References