Blesta version 6 has been released! Read More.
All posts
Security 2014-02-12 · Cody · 1 min read

Security Advisory - Staff Permission Escalation

Security advisory: a moderate staff permission escalation flaw in Blesta 3.0.0-3.0.8 and 3.1.0 lets valid staff gain permissions via crafted URLs. Fixed in 3.0.9 and 3.1.1.

Affected Versions

Versions 3.0.0 through 3.0.8, and 3.1.0 are affected.

Description

Active and valid staff members may be able to gain additional permissions through crafted URLs. Because this issue requires that the user have an active and valid staff member account, this is classified as a Moderate vulnerability. Patch release 3.0.9 and 3.1.1 corrects this vulnerability.

Resolution

If you are running 3.0.x upgrade to version 3.0.9. If you are running 3.1.0 upgrade to version 3.1.1.

Related tasks:

  1. CORE-1045

Credits

CORE-1045 was discovered by Nerijus Barauskas at NGnTC.

30-day free trial · No credit card · Your server

Read enough. Run it.

Everything on this blog ships in the box. Full product, free for 30 days, on your own server.

Download  6.0.0