Lucene search

K
wpvulndbBenachiWPVDB-ID:6D29BA12-F14A-4CEE-BAAE-A6049D83BCE6
HistoryNov 10, 2023 - 12:00 a.m.

Welcart e-Commerce < 2.9.5 - Subscriber+ Arbitrary File Upload

2023-11-1000:00:00
Benachi
wpscan.com
2
welcart e-commerce
arbitrary file upload
csrf
ajax
php file
security issue

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

Description The plugin does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload arbitrary files, such as PHP on the server

PoC

Setup (As admin): - Go the the Settlement Settings ad drag the β€œγƒšγ‚€γ‚Έγ‚§γƒ³γƒˆβ€ module to the β€˜Settlement modules in use’ section, then click the update button - Setup the module and upload a certificate Attack (as a subscriber), login to the blog, open a page with the code below and select a PHP file: This will upload the php file to the uploads/xxxxx/ folder

CPENameOperatorVersion
eq2.9.5

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

Related for WPVDB-ID:6D29BA12-F14A-4CEE-BAAE-A6049D83BCE6