What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.
Explanation of Vulnerability in Simple Terms
Manager for Icomoon versions up to 2.0 allow authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files that may affect the confidentiality, integrity, and availability of the site and potentially other systems. The vulnerability requires high-level access and does not require user interaction.
What an attacker can do
Upload malicious files to the site with admin privileges.
Potential impact on your site
A compromised admin account could upload files that damage site integrity or availability.
Conditions required to exploit
Attacker must have administrator-level access to the site.
Key dates
External resources
Related vulnerabilities