PT-2019-19274 · WordPress · Wordpress
Allyshka
·
Published
2019-02-20
·
Updated
2021-02-23
·
CVE-2019-8943
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress versions prior to 5.0.4
Description
The issue allows for Path Traversal in the
wp crop image() function. An attacker with privileges to crop an image can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences. For example, a filename ending with the .jpg?/../../file.jpg substring can be used.Recommendations
For WordPress versions prior to 5.0.4, update to version 5.0.4 or later to resolve the issue.
As a temporary workaround, consider restricting the
wp crop image() function to prevent arbitrary directory writing until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress