Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.112799
Kategorie:Web application abuses
Titel:WordPress Elegant Themes Extra Theme 2.0 <= 4.5.2 Authenticated Arbitrary File Upload Vulnerability
Zusammenfassung:The WordPress theme Extra by Elegant Themes is prone to an authenticated arbitrary file upload vulnerability.
Beschreibung:Summary:
The WordPress theme Extra by Elegant Themes is prone to an authenticated arbitrary file upload vulnerability.

Vulnerability Insight:
The theme uses a client-side file type verification check, but it was missing a server-side verification check.
This flaw made it possible for authenticated attackers to easily bypass the JavaScript client-side check and upload
malicious PHP files to a targeted website.

An attacker could easily use a malicious file uploaded via this method to completely take over a site.

Vulnerability Impact:
This flaw gave authenticated attackers, with contributor-level or above capabilities,
the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable site's server.

Affected Software/OS:
WordPress Extra theme by Elegant Themes versions 2.0 through 4.5.2.

Solution:
Update to version 4.5.3 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-35945
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.