PT-2024-36388 · WordPress · Panda Video

Matthew Rollings

+1

·

Published

2024-07-09

·

Updated

2024-07-09

·

CVE-2024-5456

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Panda Video plugin for WordPress versions up to, and including, 1.4.0
Description The issue allows authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server via the selected button parameter. This can lead to bypassing access controls, obtaining sensitive data, or achieving code execution, especially in cases where images and other “safe” file types can be uploaded and included.
Recommendations For Panda Video plugin for WordPress versions up to, and including, 1.4.0, consider disabling the plugin until a patch is available to prevent exploitation via the selected button parameter. Restrict access to the plugin's functionality to minimize the risk of arbitrary file inclusion and execution. Avoid using the selected button parameter in affected configurations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5456

Affected Products

Panda Video