PT-2023-13445 · WordPress · Imagemagick Engine Plugin
Rasoul Jahanshahi
·
Published
2023-02-09
·
Updated
2023-02-16
·
CVE-2022-3568
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick Engine plugin for WordPress versions up to, and including 1.7.5
Description
The issue allows deserialization of untrusted input via the
cli path parameter. This enables unauthenticated users to call files using a PHAR wrapper if they can trick a site administrator into performing a specific action, such as clicking on a link, which deserializes and calls arbitrary PHP Objects. This can be used for malicious actions if a POP chain is also present, and the attacker successfully uploads a file with the serialized payload.Recommendations
For versions up to, and including 1.7.5, consider disabling the
cli path parameter until a patch is available to prevent deserialization of untrusted input. Restrict access to the plugin's functionality to minimize the risk of exploitation. Avoid using the cli path parameter in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.CSRF
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imagemagick Engine Plugin