Description
i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to remove files from the server's filesystem.
Problem types
External Control of File Name or Path
Product status
Credits
Besim ALTINOK
References
www.exploit-db.com/exploits/48427 (ExploitDB-48427)
www.i-doit.org/ (Official Vendor Homepage)
sourceforge.net/projects/i-doit/ (i-doit SourceForge Project)
www.vulncheck.com/...pen-source-cmdb-arbitrary-file-deletion (VulnCheck Advisory: i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion)