CVE-2024-50525

Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint Plug your WooCommerce into the largest catalog of customized print products from Helloprint allows Upload a Web Shell to a Web Server.This issue affects Plug your WooCommerce into the largest catalog of customized print products from Helloprint: from n/a through 2.0.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:helloprint:helloprint:*:*:*:*:*:wordpress:*:*

History

06 Nov 2024, 15:42

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:helloprint:helloprint:*:*:*:*:*:wordpress:*:*
Summary
  • (es) Vulnerabilidad de carga sin restricciones de archivo con tipo peligroso en Helloprint Plug your WooCommerce al catálogo más grande de productos de impresión personalizados de Helloprint permite cargar un Web Shell a un servidor web. Este problema afecta a Plug your WooCommerce al catálogo más grande de productos de impresión personalizados de Helloprint: desde n/a hasta 2.0.2.
First Time Helloprint helloprint
Helloprint
References () https://patchstack.com/database/vulnerability/helloprint/wordpress-helloprint-plugin-2-0-2-arbitrary-file-upload-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/helloprint/wordpress-helloprint-plugin-2-0-2-arbitrary-file-upload-vulnerability?_s_id=cve - Third Party Advisory

04 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-04 14:15

Updated : 2024-11-06 15:42


NVD link : CVE-2024-50525

Mitre link : CVE-2024-50525

CVE.ORG link : CVE-2024-50525


JSON object : View

Products Affected

helloprint

  • helloprint
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type