What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: from n/a through <= 1.2.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: from n/a through <= 1.2.4.
Explanation of Vulnerability in Simple Terms
Iconize versions up to 1.2.4 allow authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files that may affect the confidentiality, integrity, and availability of the site and potentially other systems. Update to a version newer than 1.2.4.
What an attacker can do
Upload malicious files to the site and potentially run code or compromise other systems.
Potential impact on your site
A compromised admin account could upload files that damage your site, steal data, or affect connected systems.
Conditions required to exploit
Attacker must have administrator-level access to the site.
Key dates
External resources
Related vulnerabilities