CVE-2012-2670Improper Input Validation in Collabtive

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 48.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 17
Latest updateMay 17

Description

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDo-dyn/collabtive0.7.5+3

🔴Vulnerability Details

1
GHSA
GHSA-5j3c-768x-m8c6: manageuser2022-05-17
CVE-2012-2670 — Improper Input Validation in Collabtive | cvebase