CVE-2021-3120
YITH WooCommerce Gift Cards Premium <= 3.3.0 - Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a valid Gift Card product into the shopping cart. An uploaded file is placed at a predetermined path on the web server with a user-specified filename and extension. This occurs because the ywgc-upload-picture parameter can have a .php value even though the intention was to only allow uploads of Gift Card images.
Una vulnerabilidad de carga de archivos arbitraria en el plugin YITH WooCommerce Gift Cards Premium versiones anteriores a 3.3.1, para WordPress, permite a atacantes remotos lograr una ejecución de código remota en el sistema operativo en el contexto de seguridad del servidor web. A fin de explotar esta vulnerabilidad, un atacante debe poder colocar una Tarjeta de Regalo válida en el carrito de compras. Un archivo cargado se coloca en una ruta predeterminada en el servidor web con un nombre de archivo y una extensión especificados por el usuario. Esto ocurre porque el parámetro ywgc-upload-picture puede tener un valor .php aunque la intención era permitir solo la carga de imágenes de Tarjetas de Regalo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-11 CVE Reserved
- 2021-01-27 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-11-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/guy-liu/yith-giftdrop | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://yithemes.com/themes/plugins/yith-woocommerce-gift-cards | 2023-02-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Yithemes Search vendor "Yithemes" | Yith Woocommerce Gift Cards Search vendor "Yithemes" for product "Yith Woocommerce Gift Cards" | < 3.3.1 Search vendor "Yithemes" for product "Yith Woocommerce Gift Cards" and version " < 3.3.1" | premium, wordpress |
Affected
|