Skip to content

Cross-site Request Forgery (CSRF) leading to RCE in SOY CMS

High
inunosinsi published GHSA-j2qw-747j-mfv4 Sep 17, 2020

Package

SOY CMS

Affected versions

3.0.2.328

Patched versions

3.0.2.328

Description

SOY CMS 3.0.2 and earlier is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage.

Impact: CSRF to RCE via Unrestricted File Modification

  • Attack vector is: Administrator must be logged in.
  • Components are: Soy Inquiry
  • Tested SOY CMS Version : 3.0.2 (latest)
  • Affected SOY CMS Version : ~3.0.2

Found by @stypr from Vulnerability Research Team in Flatt Security Inc.

Reference:

https://youtu.be/ffvKH3gwyRE
Issue: #7
Fix PR: #15

Severity

High

CVE ID

CVE-2020-15182

Weaknesses

No CWEs

Credits