Skip to content

OS Command Injection Vulnerability in SOY CMS

High
inunosinsi published GHSA-qg3q-hfgc-5jmm Mar 8, 2024

Package

No package listed

Affected versions

Affected Versions: < 3.14.2

Patched versions

Patched Versions: 3.14.2

Description

SOY CMS version 3.14.2 is vulnerable to an OS Command Injection vulnerability within its file upload feature when accessed by an administrator. The vulnerability enables the execution of arbitrary OS commands through specially crafted file names containing a semicolon, affecting the jpegoptim functionality.

Impact: Arbitrary OS command execution via file upload

・Attack vector: Requires administrator login.
・Components affected: File upload functionality.
・Tested SOY CMS Version: 3.14.2
・Affected SOY CMS Version: < 3.14.2

Found by takuto.tanda in GMO Cybersecurity by Ierae, Inc.

Severity

High

CVE ID

CVE-2024-28187

Weaknesses

No CWEs