Redirection <= 3.6.3 - Cross-Site Request Forgery to Remote Code Execution

2018-11-14 00:00
RIPS Technologies

Strategic Overview

Status
Patched in 3.6.4
Affected PluginRedirection
Affected Version<= 3.6.3
CVSS8.8High
CVEN/A
View all Redirection vulnerabilities

Vulnerability Overview

The Redirection plugin suffers from a critical Cross-Site Request Forgery vulnerability that allows remote attackers to create a file on the target server and execute arbitrary code. The attack requires an administrator visit a malicious website set up by the attacker, but does not require more interaction nor do they have to click on anything on the malicious website in order to trigger the exploit.

Technical Analysis

REMEDIATION: Update to version 3.6.4, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C