PT-2024-36388 · WordPress · Panda Video
Matthew Rollings
+1
·
Published
2024-07-09
·
Updated
2024-07-09
·
CVE-2024-5456
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Panda Video plugin for WordPress versions up to, and including, 1.4.0
Description
The issue allows authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server via the
selected button parameter. This can lead to bypassing access controls, obtaining sensitive data, or achieving code execution, especially in cases where images and other “safe” file types can be uploaded and included.Recommendations
For Panda Video plugin for WordPress versions up to, and including, 1.4.0, consider disabling the plugin until a patch is available to prevent exploitation via the
selected button parameter. Restrict access to the plugin's functionality to minimize the risk of arbitrary file inclusion and execution. Avoid using the selected button parameter in affected configurations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Panda Video