What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
Explanation of Vulnerability in Simple Terms
Avada allows authenticated users with low privileges to upload files without proper validation, potentially enabling them to upload malicious code. The vulnerability affects versions up to 7.11.1. An attacker can bypass file type restrictions and upload executable files, compromising site integrity and confidentiality. Update to a version newer than 7.11.1 to remediate.
What an attacker can do
Upload malicious files (including executable code) to the site server.
Potential impact on your site
Attackers with basic user accounts can upload and execute code, potentially taking over the site.
Conditions required to exploit
Attacker must have a low-privilege authenticated account; no user interaction required.
Key dates
External resources
Related vulnerabilities