PT-2023-25829 · WordPress · Upload Media By Url
Dmitriy
·
Publicado
2023-08-30
·
Atualizado
2023-09-01
·
CVE-2023-3720
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Upload Media By URL WordPress plugin versions prior to 1.0.8
Description
The issue is related to the lack of a CSRF check when uploading files, which could allow attackers to make logged-in admins upload files on their behalf, including HTML containing JS code for users with the unfiltered html capability.
Recommendations
For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue. As a temporary workaround, consider restricting the
unfiltered html capability to minimize the risk of exploitation. Restrict access to file upload functionality to prevent unauthorized uploads until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Upload Media By Url