What the vulnerability does
01Description
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Explanation of Vulnerability in Simple Terms
UltimateAI versions up to 3.1.0 allow authenticated users to upload files without proper type validation. An attacker with low-level access can upload malicious files—such as executable scripts—that execute on the server. This grants the attacker full control over the site, including the ability to read, modify, or delete data, and disrupt service.
What an attacker can do
Upload and execute malicious files on the server to gain full control of the site.
Potential impact on your site
A compromised site can have all data stolen, modified, or deleted, and service disrupted.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities