CVE-2023-1112
Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222072.
Es wurde eine kritische Schwachstelle in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 für WordPress ausgemacht. Es geht dabei um eine nicht klar definierte Funktion der Datei admin-ajax.php. Durch Manipulation des Arguments upload_name mit unbekannten Daten kann eine relative path traversal-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung.
The Drag and Drop Multiple File Upload PRO plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.10.9 due to insufficient restrictions on the path supplied to the upload_dir value. This allows authenticated attackers to upload files to arbitrary locations on a webserver.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-03-01 CVE Reserved
- 2023-03-01 CVE Published
- 2023-08-01 First Exploit
- 2024-08-02 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-23: Relative Path Traversal
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.222072 | Technical Description |
URL | Date | SRC |
---|---|---|
https://github.com/codeb0ss/CVE-2023-1112-EXP | 2023-08-01 | |
https://github.com/Nickguitar/Drag-and-Drop-Multiple-File-Uploader-PRO-Path-Traversal | 2024-11-12 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Codedropz Search vendor "Codedropz" | Drag And Drop Multiple File Upload - Contact Form 7 Search vendor "Codedropz" for product "Drag And Drop Multiple File Upload - Contact Form 7" | < 5.0.6.3 Search vendor "Codedropz" for product "Drag And Drop Multiple File Upload - Contact Form 7" and version " < 5.0.6.3" | pro, wordpress |
Affected
|