Simple Image Manipulator <= 1.0 - Remote File Download

2015-08-02 00:00
Larry W. Cashdollar

Strategic Overview

Status
Unpatched
Affected Version<= 1.0
CVSS6.5Medium
CVECVE-2015-1000010
View all Simple Image Manipulator vulnerabilities

Vulnerability Overview

The Simple Image Manipulator plugin for WordPress is vulnerable to Remote File Download in versions up to, and including, 1.0. This is due to no authorization checks or user input sanitization being performed in the './simple-image-manipulator/controller/download.php' file. This makes it possible for authenticated attackers to remotely download otherwise restricted files from the vulnerable site.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C