PT-2023-25829 · WordPress · Upload Media By Url

Dmitriy

·

Publicado

2023-08-30

·

Atualizado

2023-09-01

·

CVE-2023-3720

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Upload Media By URL WordPress plugin versions prior to 1.0.8
Description The issue is related to the lack of a CSRF check when uploading files, which could allow attackers to make logged-in admins upload files on their behalf, including HTML containing JS code for users with the unfiltered html capability.
Recommendations For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue. As a temporary workaround, consider restricting the unfiltered html capability to minimize the risk of exploitation. Restrict access to file upload functionality to prevent unauthorized uploads until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-3720

Produtos afetados

Upload Media By Url