What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.
Explanation of Vulnerability in Simple Terms
Halyra CDI versions up to 5.5.3 allow authenticated administrators to upload files without proper validation. An attacker with high-level privileges can upload malicious files that may affect confidentiality, integrity, and availability of the system. The vulnerability has network-wide scope, meaning impacts may extend beyond the vulnerable component itself.
What an attacker can do
Upload malicious files to the system and potentially execute code or compromise data.
Potential impact on your site
An admin account compromise could lead to full system takeover, data theft, or service disruption.
Conditions required to exploit
Attacker must have high-level administrative privileges and network access to the application.
Key dates
External resources
Related vulnerabilities