The MediaBundle blocks dangerous upload extensions with a blacklist that was matched case-sensitively, while the stored filename was lowercased afterwards. A file uploaded as webshell.pHp therefore bypassed the blacklist and was written to the web-accessible upload directory as webshell.php, where the web server executed it. Any authenticated backend user with access to the media section could obtain remote code execution.
// detailsFileHandler::getFilePath() rewrote blacklisted extensions to .txt using a case-sensitive regex, and only then lowercased the extension when building the stored name — so the check ran against the attacker-controlled casing and the normalisation happened after it.
Two further weaknesses contributed:
- The default blacklist contained only php and htaccess, leaving other
server-executable extensions (phtml, php5, phar, shtml, cgi, …) unblocked regardless of casing.
- Configured blacklist values were interpolated into the regex unescaped.
An authenticated user with access to the admin media section can upload a file that the web server executes as PHP. The uploaded file is reachable over HTTP without authentication, giving arbitrary code execution as the web server user.
// patchesFixed in kunstmaan/media-bundle 7.3.2. The extension is now normalised before it is checked and compared with inarray(); the default blacklist is expanded to the full set of server-executable extensions; and a new opt-in allowedextensions option allows projects to enforce a strict allow-list.
Note that the patch does not rename files already stored on disk. Sites should audit their media upload directory for existing files with an executable extension.
// workaroundsIf you cannot upgrade, configure the web server to refuse to execute scripts in the media upload directory (for example a location block in nginx or phpflag engine off in Apache).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- High
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High