What the vulnerability does
01Description
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Explanation of Vulnerability in Simple Terms
Sync Post With Other Site versions up to 1.9.3 allow authenticated users to upload files without proper type validation. An attacker with low-level site access can upload malicious files (such as PHP scripts) to execute arbitrary code on the server. The vulnerability affects the entire site and any connected systems.
What an attacker can do
Upload and execute malicious files (such as PHP scripts) on the server to run arbitrary code.
Potential impact on your site
Any authenticated user can upload executable files and take control of your site, access databases, or compromise connected systems.
Conditions required to exploit
Attacker must have a low-privilege user account on the site (e.g., contributor or subscriber role).
Key dates
External resources
Related vulnerabilities