Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2023-29386

9.1CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
26 March 2024

Summary

The vulnerability in Icomoon Manager allows for unrestricted file uploads, permitting attackers to upload malicious files that can compromise the security of the web application. This flaw affects versions from earlier releases to 2.0. By exploiting this vulnerability, an attacker may plant web shells or other payloads, which could lead to further unauthorized access or control over the affected systems. It is crucial for users of Icomoon Manager to implement security measures to mitigate the risks associated with this issue.

Affected Version(s)

Manager for Icomoon <= 2.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

deokhunKim (Patchstack Alliance)
.