Unrestricted File Upload Vulnerability in SeedProd Pro by SeedProd LLC
CVE-2024-54285
9.1CRITICAL
Summary
The vulnerability identified as CVE-2024-54285 is a critical unrestricted file upload issue affecting the SeedProd Pro plugin developed by SeedProd LLC. This flaw allows attackers to upload malicious files, including web shells, to vulnerable web servers, thereby enabling remote code execution (RCE). The impact of this vulnerability is severe, as it poses significant risks to website integrity and security. Users of SeedProd Pro, particularly those using versions up to 6.18.10, should take immediate action to mitigate this risk by updating to the latest version or implementing security measures to block unauthorized file uploads.
Affected Version(s)
SeedProd Pro <= 6.18.10
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc)