PT-2024-32707 · Unknown · Thatplugin Iconize

Soprobro

·

Published

2024-10-16

·

Updated

2024-10-16

·

CVE-2024-47649

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions THATplugin Iconize versions 1.2.4 and earlier
Description The issue is related to an Unrestricted Upload of File with Dangerous Type, which affects the Iconize plugin. This allows for the upload of files with potentially dangerous types, posing a security risk.
Recommendations For versions 1.2.4 and earlier, consider restricting or disabling file upload functionality until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47649

Affected Products

Thatplugin Iconize