PT-2022-13138 · WordPress · Learnpress

Ceylan Bozogullarindan

·

Published

2022-02-28

·

Updated

2023-08-02

·

CVE-2022-0377

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions LearnPress WordPress plugin versions prior to 4.1.5
Description The issue allows users to upload an image as a profile avatar after registration, which is then cropped and saved. A "POST" request is sent to the server to rename and crop the image, changing the user-supplied image name to an MD5 value. This process is limited to JPG or PNG image types. An attacker can exploit this to rename an arbitrary image file, potentially disrupting the website's design.
Recommendations For versions prior to 4.1.5, update to version 4.1.5 or later to resolve the issue. As a temporary workaround, consider restricting the image upload functionality to trusted users or disabling the image cropping and renaming feature until the update is applied.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0377

Affected Products

Learnpress