Infusionsoft Gravity Forms Add-on 1.5.3 - 1.5.10 - Arbitrary File Upload
2014-10-06 00:00
James HookerStrategic Overview
StatusPatched in 1.5.11
Affected PluginInfusionsoft Gravity Forms Add-on
Affected Version
1.5.3 – 1.5.10CVSS9.8Critical
CVE
CVE-2014-6446Vulnerability Overview
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.
Technical Analysis
REMEDIATION: Update to version 1.5.11, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C