What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14.
Explanation of Vulnerability in Simple Terms
WP Chill Filr versions up to 1.2.14 do not properly validate uploaded files, allowing authenticated users to upload malicious files that can compromise the site. An attacker with low-level access can upload files without restriction, potentially executing code or modifying site content. The vulnerability affects multiple security properties and may impact systems beyond the vulnerable component.
What an attacker can do
Upload files without validation and execute code or modify site data.
Potential impact on your site
Compromised site integrity, data theft, and potential code execution by authenticated attackers.
Conditions required to exploit
Attacker must have a low-privilege user account; no user interaction required.
Key dates
External resources
Related vulnerabilities