We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 36893
    • 1 Posts
    Hi

    I have a few sites running on MODX 1.0.5 - 1.0.10 and i'm going to upgrade them to the latest 1.0.15 version due to security issues. But another issue has come to my attention today:

    KCFinder 2.51 - Local File Disclosure: http://www.exploit-db.com/exploits/27597/

    OSVDB.ORG (http://osvdb.org/show/osvdb/96311) says:
    KCFinder contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the browse.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'file' parameter. This directory traversal attack would allow a remote attacker to gain access to arbitrary files.

    Posted 2013-08-15, but i can not find any update or fix for the KCFinder addressing this vulnerability. Furthermore, version 2.51 is not in the list of releases, must be really outdated.

    To be honest, i have no clue how to reproduce this exploit and check if it is still there or not. Could anyone confirm this vulnerability does exists, has been fixed or not fixed? Or, even better, does it pose any risk to our MODX sites? If KCFined is vulnerable only from inside manager, i'd say this is not an issue at all (for me at least).
      • 27444 ☆ A M B ☆
      • 117 Posts
      Hi bucholtz,

      Just checked - the latest release of KCFinder is 3.1.12 - https://github.com/sunhater/kcfinder/releases

      As can be seen, it has a XSS vulnerability fix.
        Steven James McLean
        Tech Lead
        springbokagency.com
        • 13428 ☆ A M B ☆
        • 1,031 Posts
        Thanks for reporting. We will look into the code and see how to fix it.
          • 13428 ☆ A M B ☆
          • 1,031 Posts
          That KCFinder vulnerability was already patched in MODX (https://github.com/modxcms/evolution/commit/5711c318ec0f0db28723c1328d46a15e547827be). Inside of the file parameter directory traversal is not allowed. And KCFinder is only executable in a valid manager session. [ed. note: Jako last edited this post 11 years, 10 months ago.]
            • 27444 ☆ A M B ☆
            • 117 Posts
            Hi Jako,

            Seems like Mod_Security is stopping the upload functionality of the KCFinder packaged in MODX 1.0.15 (it didn't in previous versions).

            Is there a solution to it without disabling the Mod_Security?
              Steven James McLean
              Tech Lead
              springbokagency.com
              • 13428 ☆ A M B ☆
              • 1,031 Posts
                • 1343 ☆ A M B ☆
                • 2,213 Posts
                Quote from: sjmclean at Nov 22, 2014, 03:51 PM
                Is there a solution to it without disabling the Mod_Security?

                Do you know what rules are being triggered? Once you know the offending rule action can be taken to avoid the problem (rewrite the rule, disable the rule, or update the code to avoid triggering the rule).
                  Patrick | Server Wrangler
                  About Me: Website | Tweets |  MODX Hosting
                  • 27444 ☆ A M B ☆
                  • 117 Posts
                  Yes, it's giving the following:

                  GET:
                  /manager/media/browser/mcpuk/browse.php?type=images&lng=en&act=upload HTTP/1.1

                  MESSAGE:
                  Access denied with code 44 (phase 2). Match of "eq 0" against "MULTIPART_STRICT_ERROR" required. [file "/usr/local/apache/conf/modsec2.conf"] [line "23"] [id "1234123456"] [msg "Multipart request body failed strict validation: PE 0, BQ 0, BW 0, DB 0, DA 0, HF 0, LF 0, SM 0, IQ 0, IP 1, IH 0, FL 0"]

                  ACTION:
                  404

                  Will check with my host.
                    Steven James McLean
                    Tech Lead
                    springbokagency.com
                    • 27444 ☆ A M B ☆
                    • 117 Posts
                    UPDATE

                    I have added the following in the Mod_Sec and the KCFinder worked:

                    <Directory /home/user/public_html/manager/media/browser/mcpuk>
                    SecRuleRemoveById 1234123456
                    </Directory>

                    QUESTION

                    Am I exposing my website to security issues on this website by applying such a rule?
                      Steven James McLean
                      Tech Lead
                      springbokagency.com
                      • 1343 ☆ A M B ☆
                      • 2,213 Posts
                      You are being very specific in disabling the rule in question, so the impact to security should be minimal. I would be interested to know what ruleset (if any) is being used, and what's the actual rule in question. It sounds like there is some aspect of the request getting flagged, which could be correctable.
                        Patrick | Server Wrangler
                        About Me: Website | Tweets |  MODX Hosting