{ "Name": "Chemex Auth File Upload CNVD-2021-15573", "Description": "

Coffee pot Chemex is a free, open source, efficient and beautiful IT operation and maintenance management platform.

Chemex has a background file upload vulnerability(default login admin:admin), which can be exploited by attackers to gain control of the server.

", "Product": "Chemex", "Homepage": "https://gitee.com/dcat-phper/chemex", "DisclosureDate": "2021-02-02", "Author": "1291904552@qq.com", "FofaQuery": "(title=\"咖啡壶\" || body=\"让IT资产管理更加简单\") && body=\"CreateDcat\"", "GobyQuery": "(title=\"咖啡壶\" || body=\"让IT资产管理更加简单\") && body=\"CreateDcat\"", "Level": "3", "Impact": "

Chemex has a background file upload vulnerability, which can be exploited by attackers to gain control of the server.

", "Recommandation": "

The vendor has released a bug fix, please pay attention to the update in time: https://gitee.com/dcat-phper/chemex/

1. Set access policies and whitelist access through security devices such as firewalls.

2.If not necessary, prohibit public network access to the system.

", "Translation": { "CN": { "Name": "Chemex 文件上传漏洞 CNVD-2021-15573", "VulType": ["文件上传"], "Description": "

咖啡壶Chemex是一个免费、开源、高效且漂亮的IT运维管理平台。

Chemex存在后台文件上传漏洞,默认密码(admin:admin)攻击者可利用该漏洞获取服务器控制权。

", "Impact": "

Chemex存在后台文件上传漏洞,攻击者可利用该漏洞获取服务器控制权。

", "Product": "咖啡壶", "Recommendation": "

⼚商已发布了漏洞修复程序,请及时关注更新:https://gitee.com/dcat-phper/chemex

1、通过防⽕墙等安全设备设置访问策略,设置⽩名单访问。

2、如⾮必要,禁⽌公⽹访问该系统。

" }, "EN": { "Name": "Chemex Auth File Upload CNVD-2021-15573", "VulType": ["fileupload"], "Description": "

Coffee pot Chemex is a free, open source, efficient and beautiful IT operation and maintenance management platform.

Chemex has a background file upload vulnerability(default login admin:admin), which can be exploited by attackers to gain control of the server.

", "Impact": "

Chemex has a background file upload vulnerability, which can be exploited by attackers to gain control of the server.

", "Product": "Chemex", "Recommendation": "

The vendor has released a bug fix, please pay attention to the update in time: https://gitee.com/dcat-phper/chemex/

1. Set access policies and whitelist access through security devices such as firewalls.

2.If not necessary, prohibit public network access to the system.

" } }, "References": [ "https://www.cnvd.org.cn/flaw/show/CNVD-2021-15573" ], "HasExp": true, "ExpParams": null, "ExpTips": { "Type": "", "Content": "" }, "ScanSteps": null, "ExploitSteps": null, "Tags": [ "fileupload" ], "CVEIDs": null, "CVSSScore": "0.0", "AttackSurfaces": { "Application": ["Chemex"], "Support": null, "Service": null, "System": null, "Hardware": null } }