What does it actually mean when we talk about CVE, short for Common Vulnerability Exposures?
Let’s break it down:
To simplify it, imagine a popular type of lock that is used in many houses, and suddenly it is discovered that it can be unlocked with a simple paperclip. In this case, CVE would be a warning to all users of that lock to let them know about the error and get instructions on how to fix it or replace the lock. This is where our ethical hacker Andrej comes in, who after identifying and reporting the vulnerability, obtained 3 CVE ID numbers that specifically name his find. The ability and expertise needed to find and identify CVEs underlines our motto: hackers on your side!
CVE-2022-37830: Stored XSS in WebJET CMS
CVE-2022-38484: Path Traversal vulnerability in AgeVolt portal
The second discovery, CVE-2022-38484, a critical (9.1 CVSS score) vulnerability in AgeVolt Portal, allowed attackers to upload files anywhere in the system. This posed a serious risk of unauthorized access and potential remote code execution (RCE), which allows an attacker to have control of the vulnerable server and could then exploit it to break into the company or attack any system on the Internet.
Solution: countermeasures include strict validation and sanitization of inputs, maintaining a list of allowed file types and file extensions, applying strict file type controls, and separating uploaded files in a secure, restricted directory.
CVE-2022-38485: Disclosure of information in the AgeVolt portal
Finally, CVE-2022-38485, with a severity score of 6.8, was an information disclosure vulnerability caused by directory traversal in the AgeVolt portal that allows attackers to read files from anywhere on the system.
Solution: Mitigation strategies are similar to CVE-2022-38484 and emphasize input validation, sanitization, use of whitelists, and securely storing uploaded files in dedicated directories.
At Citadelo, we have a large team of experienced ethical hackers just like Andrej who scored his recent CVE hattrick. We are proud to say that finding and helping with CVEs is not uncommon with us, as we have identified more than 20 of them during our practice.
So, If you want to put your cybersecurity to a proper test by our expert team of ethical hackers, get in touch with us today! We are Citadelo - hackers on your side.