What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
Explanation of Vulnerability in Simple Terms
Slider Revolution versions up to 6.6.15 do not properly validate file uploads, allowing administrators to upload malicious files to the site. An attacker with admin access and user interaction (such as visiting a crafted page) can upload files that compromise the site's confidentiality, integrity, and availability. Sites using this plugin should update immediately.
What an attacker can do
Upload malicious files to the site and execute code with site-wide impact.
Potential impact on your site
A compromised admin account can upload files that read data, modify content, or disable the site.
Conditions required to exploit
Attacker must have administrator privileges and the site admin must visit a malicious page or link.
Key dates
External resources
Related vulnerabilities