Infusionsoft Gravity Forms Add-on 1.5.3 - 1.5.10 - Arbitrary File Upload

2014-10-06 00:00
James Hooker

Strategic Overview

Status
Patched in 1.5.11
Affected Version1.5.3 – 1.5.10
CVSS9.8Critical
CVECVE-2014-6446
View all Infusionsoft Gravity Forms Add-on vulnerabilities

Vulnerability Overview

The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.

Technical Analysis

REMEDIATION: Update to version 1.5.11, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C