PT-2024-35269 · Anton Hoelstad · Wp Quick Setup

Mika

·

Published

2024-11-18

·

Updated

2024-11-20

·

CVE-2024-52429

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anton Hoelstad WP Quick Setup versions 2.0 and earlier
Description The issue allows an attacker to upload a web shell to a web server, potentially leading to unauthorized access. This is due to an unrestricted upload of file with dangerous type vulnerability.
Recommendations For versions 2.0 and earlier, update to version 2.1 immediately to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent potential exploitation until the update can be applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-52429

Affected Products

Wp Quick Setup