Unrestricted Upload of File with Dangerous Type Vulnerability Affects Computer Repair Shop
CVE-2024-51793
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 11 November 2024
Badges
What is CVE-2024-51793?
The vulnerability in Webful Creations' Computer Repair Shop allows attackers to perform unrestricted file uploads. This security flaw can be exploited to upload a web shell to the web server, enabling unauthorized access and control over the server. The issue primarily affects versions from n/a through 3.8115 of the Computer Repair Shop product, making it essential for users to take immediate action to secure their systems against this threat.
Affected Version(s)
Computer Repair Shop <= 3.8115
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
53% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved