PT-2023-12463 · WordPress · Pwa For Wp & Amp

·

CVE-2021-4354

·

Publicado

2023-06-07

·

Atualizado

2023-06-14

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PWA for WP & AMP for WordPress versions up to, and including, 1.7.32
Description The issue is related to arbitrary file uploads due to missing file type validation in the pwaforwp splashscreen uploader function. This allows authenticated attackers to upload arbitrary files on the affected site's server, potentially making remote code execution possible.
Recommendations For versions up to, and including, 1.7.32, update to a version that includes the fix for the missing file type validation in the pwaforwp splashscreen uploader function to prevent arbitrary file uploads.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-4354

Produtos afetados

Pwa For Wp & Amp