What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.
Explanation of Vulnerability in Simple Terms
Photo Engine versions up to 6.4.9 allow authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files that affect confidentiality, integrity, and availability across the system. Update to a version newer than 6.4.9.
What an attacker can do
Upload malicious files to compromise the site's confidentiality, integrity, and availability.
Potential impact on your site
An admin account compromise could allow file uploads that damage or take over your entire site.
Conditions required to exploit
Attacker must have administrator-level access to the site.
Key dates
External resources
Related vulnerabilities