Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grmv-gp4f-w59q

Опубликовано: 26 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

EPSS

Процентиль: 100%
0.90199
Критический

8.1 High

CVSS3

Дефекты

CWE-306
CWE-434

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

CVSS3: 8.1
fstec
около 5 лет назад

Уязвимость функции add_custom_font плагина редактирования шаблонов веб-сайтов Tatsu Builder системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.90199
Критический

8.1 High

CVSS3

Дефекты

CWE-306
CWE-434