漏洞标题
Brizy – Page Builder <= 2.6.4 版本存在已认证 (Contributor+) 任意文件上传漏洞
漏洞描述信息
WordPress用的Brizy – Page Builder插件在所有版本中,包括2.6.4版本,存在任意文件上传漏洞。该漏洞是由于'storeUploads'函数中缺少文件类型验证导致的。这使得具有Contributor级别及以上访问权限的认证攻击者可以在受影响站点的服务器上上传任意文件,从而可能导致远程代码执行。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
危险类型文件的不加限制上传
漏洞标题
Brizy – Page Builder <= 2.6.4 - Authenticated (Contributor+) Arbitrary File Upload via storeUploads
漏洞描述信息
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
漏洞类别
危险类型文件的不加限制上传