Arbitrary File Upload Vulnerability in Divi Builder and Divi Theme by Elegant Themes
CVE-2020-35945
9.9CRITICAL
Summary
A vulnerability exists in the Divi Builder plugin, along with the Divi theme and Divi Extra theme, that allows authenticated users with contributor-level permissions or higher to upload arbitrary files, including potentially malicious PHP files. This exploitation occurs due to an insufficient server-side validation process, as the file extension checks are handled on the client side. This flaw can significantly compromise site security, enabling attackers to execute code on the server and gain unauthorized access or control over the site.
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved