8.8

CVE-2021-24253

Exploit

Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCE

classyfrieds <= 3.8 - Arbitrary File Upload

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.
Mögliche Gegenmaßnahme
classyfrieds: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Classyfrieds ProjectClassyfrieds SwPlatformwordpress Version <= 3.8
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt classyfrieds
Version *-3.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.91% 0.771
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://github.com/jinhuang1102/CVE-ID-Reports/blob/master/classyfrieds.md
Third Party Advisory
Exploit
https://wpscan.com/vulnerability/ee42c233-0ff6-4b27-a5ec-ad3246bef079
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/8185c7a4-3d8e-4a24-9746-536337afbcfe
Third Party Advisory