The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files (not including PHP files) on the affected site's server which may make remote code execution possible. This can be paired with a registration endpoint for unauthenticated users to exploit the issue.
References
Configurations
History
18 Sep 2024, 15:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L1053 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3147900/mstore-api/trunk/controllers/flutter-user.php - Patch | |
References | () https://plugins.trac.wordpress.org/changeset/3147900/mstore-api/trunk/functions/index.php - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/fe3834a6-a6f5-4cc7-951e-a6ada6346b07?source=cve - Third Party Advisory | |
First Time |
Inspireui mstore Api
Inspireui |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:* | |
Summary |
|
13 Sep 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-13 15:15
Updated : 2024-09-18 15:47
NVD link : CVE-2024-8242
Mitre link : CVE-2024-8242
CVE.ORG link : CVE-2024-8242
JSON object : View
Products Affected
inspireui
- mstore_api
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type