oss-sec mailing list archives
CVE Request - Arbitrary file upload in Wordpress Plugin: N-Media file uploader v3.7
From: Sebastian Wolfgang Kraemer | HSASec <Sebastian.Kraemer () HS-Augsburg de>
Date: Wed, 10 Jun 2015 15:45:37 +0200
Greetings, we discovered a vulnerability in the following component and want to request a CVE for it: Product-Type: Wordpress Plugin Product: N-Media file uploader (https://wordpress.org/plugins/nmedia-user-file-uploader/) Version: up to 3.7 Vendor: N-Media (http://najeebmedia.com/) Fixed: fixed in version 3.8 Changelog: Version 3.8 not documented in changelog PoC available: yes Researchers: * Michael Kapfer (https://www.HSASec.de) * Sebastian Kraemer (https://www.HSASec.de) Description: This plugin enables users to upload files to a wordpress-instance and share it with the wordpress-admin. Through insufficient input validation an unauthenticated attacker is able to bypass the restriction and upload arbitrary content. This uploaded content can be executed by calling the url of the file in the public available upload directory. Best regards, the HSASec-Team (https://www.hsasec.de)
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
Current thread:
- CVE Request - Arbitrary file upload in Wordpress Plugin: N-Media file uploader v3.7 Sebastian Wolfgang Kraemer | HSASec (Jun 10)