OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior of the application as it only allows authenticated admins to upload files.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.opensource-socialnetwork.org/ | vendor advisory |
https://github.com/opensource-socialnetwork/opensource-socialnetwork/releases/tag/6.3 | third party advisory release notes |
https://www.openteknik.com/contact?channel=ossn | vendor advisory |
https://grimthereaperteam.medium.com/cve-2022-34965-open-source-social-network-6-3-3f61db82880 | third party advisory exploit |