Lucene search

K
wpvulndbWpvulndbWPVDB-ID:15D9073D-9259-479E-AF5D-9102C3A1E0E9
HistoryJan 17, 2024 - 12:00 a.m.

AI Engine: ChatGPT Chatbot < 1.9.99 - Unauthenticated Arbitrary File Upload

2024-01-1700:00:00
wpscan.com
14
vulnerable
arbitrary file upload
missing file type validation
unauthenticated attackers
remote code execution
software

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin is vulnerable to arbitrary file uploads due to missing file type validation in the ‘rest_upload’ function in all versions up to, and including, 1.9.98. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site’s server which may make remote code execution possible.

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:15D9073D-9259-479E-AF5D-9102C3A1E0E9