Junglewise Threat Intelligence

CVE-2017-5541: Symphony CMS directory traversal in usererror.missing_extension.php

CVE-2017-5541 · Severity: medium · CVSS 5.3 · Published 2017-01-20

Executive brief

Symphony CMS, a content management system used for building websites, contains a security flaw in its error handling templates. An attacker can exploit this to rename files on the web server without authorization. This could lead to website defacement, broken functionality, or the disabling of security controls by moving critical system files.

Technical details

A directory traversal vulnerability exists in the 'template/usererror.missing_extension.php' component of Symphony CMS. The root cause is insufficient sanitization of the 'existing-folder' and 'new-folder' parameters, which are susceptible to dot-dot-slash (../) sequences. A remote, unauthenticated attacker can exploit this flaw to perform arbitrary file renaming operations on the server. This can be used to disrupt site operations or manipulate file structures. The issue is resolved in version 2.6.10.

Affected products

  • Symphony CMS Symphony CMS before 2.6.10

Timeline

  • 2017-01-17: patched: Version 2.6.10 released to fix path traversal and XSS vulnerabilities.
  • 2017-01-20: disclosed: Initial NVD publication.

References

Related threats