PT-2017-14652 · Accesspress · Accesskeys Accesspress Anonymous Post Pro
Colette Chamberland
·
Published
2017-12-18
·
Updated
2018-01-12
·
CVE-2017-16949
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AccessKeys AccessPress Anonymous Post Pro plugin versions through 3.1.9
Description
The issue is related to improper input sanitization, allowing an attacker to override settings for allowed file extensions and upload file size. This is due to vulnerabilities in the inc/cores/file-uploader.php and file-uploader/file-uploader-class.php files. An attacker can upload any file to the server, including .php files, by sending a request to the "action=ap file upload action&allowedExtensions[]=php" endpoint at "/wp-admin/admin-ajax.php", resulting in PHP code execution.
Recommendations
For AccessKeys AccessPress Anonymous Post Pro plugin versions through 3.1.9, update to a version later than 3.1.9 to resolve the issue.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accesskeys Accesspress Anonymous Post Pro