PT-2024-33470 · Vivek Tamrakar · Wp Rest Api Fns
Stealthcopter
·
Published
2024-10-20
·
Updated
2024-10-24
·
CVE-2024-49329
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vivek Tamrakar WP REST API FNS versions 1.0.0 and earlier
Description
The issue allows attackers to upload harmful content, including web shells, to a web server due to an Unrestricted Upload of File with Dangerous Type vulnerability. This can be exploited by uploading a web shell, which could lead to further malicious activities.
Recommendations
For versions 1.0.0 and earlier, update to version 1.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the upload functionality until the update is applied.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Rest Api Fns