Imagements <= 1.2.5 - Arbitrary File Upload

2021-04-08 00:00
Jin Huang

Strategic Overview

Status
Unpatched
Affected PluginImagements
Affected Version<= 1.2.5
CVSS9.8Critical
CVECVE-2021-24236
View all Imagements vulnerabilities

Vulnerability Overview

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C