PT-2021-7954 · Wpanel 4 · Wpanel 4

Admin

·

Published

2021-06-05

·

Updated

2022-04-08

·

CVE-2021-34257

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WPanel 4 versions 4.3.1 and below
Description The issue is related to the lack of restrictions on file uploads, allowing a remote attacker to execute arbitrary code by uploading a malicious PHP file. This can be done through various image upload features, including the Dashboard's Avatar image, Posts Folder image, Pages Folder image, and Gallery Folder image.
Recommendations For WPanel 4 versions 4.3.1 and below, consider disabling the image upload features for the Dashboard's Avatar, Posts Folder, Pages Folder, and Gallery Folder until a patch is available. Restrict access to these features to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07225
CVE-2021-34257
GHSA-VHGR-GFX3-FG37

Affected Products

Wpanel 4