Lucene search

K
wpvulndbRamuel GallWPVDB-ID:ED4288A1-F7E4-455F-B765-5AC343F87194
HistoryMar 04, 2021 - 12:00 a.m.

WooCommerce Upload Files < 59.4 - Unauthenticated Arbitrary File Upload

2021-03-0400:00:00
Ramuel Gall
wpscan.com
10

0.002 Low

EPSS

Percentile

58.8%

The plugin ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a “blocked” extension within another “blocked” extension in the “wcuf_file_name” parameter. It was also possible to perform a double extension attack and upload files to a different location via path traversal using the “wcuf_current_upload_session_id” parameter.

CPENameOperatorVersion
woocommerce-upload-fileslt59.4

0.002 Low

EPSS

Percentile

58.8%

Related for WPVDB-ID:ED4288A1-F7E4-455F-B765-5AC343F87194