Lucene search

K
wpvulndbMinhtuanactWPVDB-ID:43AA30BF-EAF8-467A-93A1-78F9BDB37B36
HistoryOct 11, 2020 - 12:00 a.m.

PowerPress < 8.3.8 - Authenticated Arbitrary File Upload leading to RCE

2020-10-1100:00:00
minhtuanact
wpscan.com
6
powerpress
plugin
arbitrary file upload
rce
authenticated
vulnerability
admin+
php
feed images

EPSS

0.001

Percentile

44.4%

The plugin did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

PoC

https://drive.google.com/file/d/1fyf6blzeG3VX22BQX7hc1QJ20rCY5p43/view?usp=sharing - Save the below HTML code in an HTML file - Replace the to the correct one - Logon to the blog as admin, go to the Blubrry PowerPress Settings > Feeds and get the nonce from the source of the page (Look for "_wpnonce) and replace by it’s value in the saved code - Open the saved HTML file with the same browser used to login to the blog, and click on ‘Submit request’ - Then open /wp-content/uploads/powerpress/up.php in the browser

EPSS

0.001

Percentile

44.4%

Related for WPVDB-ID:43AA30BF-EAF8-467A-93A1-78F9BDB37B36