Lucene search

K
cveWPScanCVE-2021-24236
HistoryMay 06, 2021 - 1:15 p.m.

CVE-2021-24236

2021-05-0613:15:11
CWE-434
WPScan
web.nvd.nist.gov
41
imagements
wordpress
plugin
cve
nvd
security
vulnerability
rce
file upload
unauthenticated
attack

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.178

Percentile

96.2%

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

Affected configurations

Nvd
Vulners
Node
imagements_projectimagementsRange1.2.5wordpress
VendorProductVersionCPE
imagements_projectimagements*cpe:2.3:a:imagements_project:imagements:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "product": "Imagements",
    "vendor": "williewonka",
    "versions": [
      {
        "lessThanOrEqual": "1.2.5",
        "status": "affected",
        "version": "1.2.5",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.178

Percentile

96.2%