CVE-2019-19988
Summary
| CVE | CVE-2019-19988 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-26 16:15:00 UTC |
| Updated | 2020-02-27 15:02:00 UTC |
| Description | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to create and write XML files on the filesystem via /common/vam_editXml.php in the web interface. The vulnerable PHP page checks none of these: the parameter that identifies the file name to be created, the destination path, or the extension. Thus, an attacker can manipulate the file name to create any type of file within the filesystem with arbitrary content. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Seling | Visual Access Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Controllo accessi, rilevazione presenze e Building Security - Selesta Ingegneria | MISC | www.seling.it | Product |
| Applicativo Controllo Accessi: VAM - Selesta Ingegneria | MISC | www.seling.it | Product, Vendor Advisory |
| Gruppo TIM | Vulnerability Research & Advisor | MISC | www.telecomitalia.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.