What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.
Explanation of Vulnerability in Simple Terms
Corsa versions up to 1.5 allow authenticated users to upload files without proper validation. An attacker with low-level access can upload malicious files to the server, potentially executing code or compromising the site. The vulnerability requires valid login credentials but no additional user interaction.
What an attacker can do
Upload and execute malicious files on the server to run code or steal data.
Potential impact on your site
Compromised site integrity, data theft, and potential malware distribution if an attacker gains any user account.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities