The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056 | Exploit Third Party Advisory |
http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056 - Exploit, Third Party Advisory |
07 Nov 2023, 04:11
Type | Values Removed | Values Added |
---|---|---|
CWE |
02 Aug 2023, 15:42
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry |
25 Jul 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 Jul 2023, 14:51
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:advancedfilemanager:file_manager_advanced_shortcode:*:*:*:*:*:wordpress:*:* | |
References | (MISC) https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056 - Exploit, Third Party Advisory | |
First Time |
Advancedfilemanager
Advancedfilemanager file Manager Advanced Shortcode |
27 Jun 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-27 14:15
Updated : 2024-11-21 07:57
NVD link : CVE-2023-2068
Mitre link : CVE-2023-2068
CVE.ORG link : CVE-2023-2068
JSON object : View
Products Affected
advancedfilemanager
- file_manager_advanced_shortcode
CWE
No CWE.