VikBooking Hotel Booking Engine & PMS <= 1.5.8 - Arbitrary File Upload
2022-04-21 00:00
Gabriel3476Strategic Overview
StatusPatched in 1.5.9
Affected PluginVikBooking Hotel Booking Engine & PMS
Affected Version
< 1.5.8CVSS5.5Medium
CVE
CVE-2022-1409Vulnerability Overview
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code
Technical Analysis
REMEDIATION: Update to version 1.5.9, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C