PT-2024-34302 · Unknown · Woocommerce+1

Stealthcopter

·

Published

2024-11-04

·

Updated

2024-11-06

·

CVE-2024-50525

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Plug your WooCommerce into the largest catalog of customized print products from Helloprint versions n/a through 2.0.2
Description: The issue allows an attacker to upload a web shell to a web server due to an unrestricted upload of file with dangerous type vulnerability. This vulnerability can be exploited by uploading malicious files, potentially leading to server compromise. The estimated number of potentially affected devices is not specified.
Recommendations: Update to version 2.0.3 to fix the vulnerability. As a temporary workaround, consider restricting file uploads or disabling the vulnerable plugin until the update is applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-50525

Affected Products

Helloprint
Woocommerce