IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
The CWE-459 (Incomplete Cleanup) type vulnerability is located in the file \system\modules\dashboard\controllers\LoginController.php. An attacker, without needing any privileges or user interaction, can send a specially crafted request over the network via the remote interface, which will cause deletion of a file specified by the attacker on the server. The lack of validation mechanisms or proper data sanitization enables manipulation of the file path to be deleted.
An attacker can delete any file accessible to the web server process, which may lead to application disruption, data loss, or system integrity compromise. CVSS vectors indicate a high impact on system integrity (I:H) and availability (A:H).
Apply patches available from the vendor according to the references. It is recommended to monitor the official IBOS project repository at https://gitee.com/ibos/IBOS for updates. Until the fix is applied, it is recommended to restrict network access to the login panel and monitor unexpected file operations on system files.
IBOS version 4.5.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HIbos
APPIbos4.5.5
Related vulnerabilities
IBOS 4.5.4 — Arbitrary File Inclusion umożliwiające zdalne wykonanie kodu
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
A vulnerability, which was classified as critical, was found in IBOS OA 4.5.5. This affects an unknown part of...
A vulnerability, which was classified as critical, has been found in IBOS OA 4.5.5. Affected by this issue is ...
A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown...