PT-2022-13138 · WordPress · Learnpress
Ceylan Bozogullarindan
·
Published
2022-02-28
·
Updated
2023-08-02
·
CVE-2022-0377
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LearnPress WordPress plugin versions prior to 4.1.5
Description
The issue allows users to upload an image as a profile avatar after registration, which is then cropped and saved. A "POST" request is sent to the server to rename and crop the image, changing the user-supplied image name to an MD5 value. This process is limited to JPG or PNG image types. An attacker can exploit this to rename an arbitrary image file, potentially disrupting the website's design.
Recommendations
For versions prior to 4.1.5, update to version 4.1.5 or later to resolve the issue. As a temporary workaround, consider restricting the image upload functionality to trusted users or disabling the image cropping and renaming feature until the update is applied.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Learnpress