7.2
CVE-2022-0537
- EPSS 1.48%
- Veröffentlicht 04.04.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:38:52
- CVE-Watchlists
- Unerledigt
MapPress Maps for WordPress < 2.73.13 - Admin+ File Upload to Remote Code Execution
MapPress Maps for WordPress <= 2.73.12 - Admin+ File Upload to Remote Code Execution
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is added. No validation is performed on the content of the file, triggering an RCE vulnerability by uploading a web shell. Further the name parameter is not sanitized, allowing the payload to be uploaded to any directory to which the server has write access.
Mögliche Gegenmaßnahme
MapPress – Google Maps, OpenStreetMap & Leaflet: Update to version 2.73.13, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mappresspro ≫ Mappress SwPlatformwordpress Version < 2.73.13
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
MapPress – Google Maps, OpenStreetMap & Leaflet
Version
[*, 2.73.13)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.48% | 0.706 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://wpscan.com/vulnerability/abfbba70-5158-4990-98e5-f302361db367
https://www.wordfence.com/threat-intel/vulnerabilities/id/62ac66d8-fc10-4ec2-a567-7b95eb6f2c76