PT-2024-33623 · Unknown · Ai Postpix
Theviper17
·
Published
2024-10-23
·
Updated
2024-10-25
·
CVE-2024-49671
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AI Image Generator for Your Content & Featured Images – AI Postpix versions 1.1.8 and earlier
Description
The issue allows for the unrestricted upload of files with dangerous types, potentially enabling an attacker to upload a web shell to a web server. This could lead to further exploitation.
Recommendations
For versions 1.1.8 and earlier, update to a version that fixes this issue, as using an unrestricted file upload functionality poses a significant risk. As a temporary workaround, consider restricting or disabling the file upload feature until a patch is available.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai Postpix