WordPress MailPoet Newsletters Plugin Remote File Upload Vulnerability
BID:68310
Info
WordPress MailPoet Newsletters Plugin Remote File Upload Vulnerability
| Bugtraq ID: | 68310 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-4725 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2014 12:00AM |
| Updated: | Jul 09 2014 12:05AM |
| Credit: | Sucuri |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress MailPoet Newsletters Plugin Remote File Upload Vulnerability
The MailPoet Newsletters plugin for WordPress is prone to a remote file-upload vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
WordPress MailPoet Newsletters Plugin prior to 2.6.7 are vulnerable.
The MailPoet Newsletters plugin for WordPress is prone to a remote file-upload vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
WordPress MailPoet Newsletters Plugin prior to 2.6.7 are vulnerable.
Exploit / POC
WordPress MailPoet Newsletters Plugin Remote File Upload Vulnerability
Attackers can use a browser to exploit this issue.
The following metasploit module is available:
Attackers can use a browser to exploit this issue.
The following metasploit module is available:
Solution / Fix
WordPress MailPoet Newsletters Plugin Remote File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress MailPoet Newsletters Plugin Remote File Upload Vulnerability
References:
References: