THREAT OPS › Threat News › [GHSA] GHSA-ghvf-qf6h-g8x5 (high) — NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
[GHSA] GHSA-ghvf-qf6h-g8x5 (high) — NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
GHSA-ghvf-qf6h-g8x5 Severity: high CVE: None
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
## Executive Summary
Two vulnerabilities were identified and chained to achieve authenticated remote code execution
The first vulnerability allows any authenticated admin to redirect the file upload storage root to an arbitrary path on disk including the
MITRE ATT&CK techniques
Indicators of compromise
- http://192.168.228.130:13000/api/storagesurl
- http://192.168.228.130:13000/api/storages:update?filterByTk=366584416632832url
- http://192.168.228.130:13000/api/attachments:uploadurl
- http://TARGET:13000/api/pm:enable?filterByTk=/etc/passwdurl
Original source: https://github.com/advisories/GHSA-ghvf-qf6h-g8x5