ImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to Remote Command Execution

2022-10-17 00:00
Rasoul Jahanshahi

Strategic Overview

Status
Patched in 1.7.6
Affected PluginImageMagick Engine
Affected Version<= 1.7.5
CVSS8.8High
CVECVE-2022-2441
View all ImageMagick Engine vulnerabilities

Vulnerability Overview

The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they can trick a site administrator into performing an action such as clicking on a link. This makes it possible for an attacker to create and or modify files hosted on the server which can easily grant attackers backdoor access to the affected server.

Technical Analysis

REMEDIATION: Update to version 1.7.6, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C