7.2

CVE-2021-25119

Exploit

AGIL <= 1.0 - Admin+ Arbitrary File Upload

AGIL(Automatic Grid Image Listing) <= 1.0 - Arbitrary File Upload

The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
Mögliche Gegenmaßnahme
AGIL(Automatic Grid Image Listing): No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpsocketAutomatic Grid Image Listing SwPlatformwordpress Version <= 1.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt AGIL(Automatic Grid Image Listing)
Version *-1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.44% 0.697
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://wpscan.com/vulnerability/47235989-d9f1-48a5-9799-fdef0889bf8a
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/a75c179f-236b-4a1b-8566-b74e0c5fda27
Third Party Advisory