The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056 | Exploit Third Party Advisory |
http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-06-27 14:15
Updated : 2024-11-21 07:57
NVD link : CVE-2023-2068
Mitre link : CVE-2023-2068
CVE.ORG link : CVE-2023-2068
JSON object : View
Products Affected
advancedfilemanager
- file_manager_advanced_shortcode
CWE
No CWE.