CVE-2024-3112

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Configurations

Configuration 1 (hide)

cpe:2.3:a:bestwebsoft:quotes_and_tips:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/fa6f01d6-aa3b-4452-9c5f-49bb227fea9d/ - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/fa6f01d6-aa3b-4452-9c5f-49bb227fea9d/ - Exploit, Third Party Advisory

24 Jul 2024, 20:03

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CPE cpe:2.3:a:bestwebsoft:quotes_and_tips:*:*:*:*:*:wordpress:*:*
First Time Bestwebsoft quotes And Tips
Bestwebsoft
References () https://wpscan.com/vulnerability/fa6f01d6-aa3b-4452-9c5f-49bb227fea9d/ - () https://wpscan.com/vulnerability/fa6f01d6-aa3b-4452-9c5f-49bb227fea9d/ - Exploit, Third Party Advisory

12 Jul 2024, 12:49

Type Values Removed Values Added
Summary
  • (es) El complemento Quotes and Tips by BestWebSoft para WordPress anterior a la 1.45 no valida correctamente los archivos de imagen cargados, lo que permite a usuarios con privilegios elevados, como el administrador, cargar archivos arbitrarios en el servidor incluso cuando no se les debería permitir (por ejemplo, en una configuración multisitio).

12 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-12 06:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-3112

Mitre link : CVE-2024-3112

CVE.ORG link : CVE-2024-3112


JSON object : View

Products Affected

bestwebsoft

  • quotes_and_tips
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type