PT-2024-33609 · Unknown · Ecomerciar Woocommerce Custom Profile Picture

Stealthcopter

·

Published

2024-10-23

·

Updated

2024-10-25

·

CVE-2024-49658

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ecomerciar Woocommerce Custom Profile Picture versions 1.0 and earlier
Description The issue allows for the unrestricted upload of files with dangerous types, enabling an attacker to upload a web shell to a web server.
Recommendations For Ecomerciar Woocommerce Custom Profile Picture versions 1.0 and earlier, update to a version that contains a fix for this issue, if available. If no fixed version is available, consider restricting file uploads to only necessary and safe file types as a temporary mitigation measure.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-49658

Affected Products

Ecomerciar Woocommerce Custom Profile Picture