Arbitrary file upload in WP Live Chat Support - CVE-2018-12426

 

Arbitrary file upload in WP Live Chat Support - CVE-2018-12426

Published: May 17, 2019


Vulnerability identifier: #VU18516
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12426
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to absent validation of file extension when uploading files via v1/remote_upload request. A remote attacker can upload and execute arbitrary .php file on the server and execute it.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

WP Live Chat Support

How to mitigate CVE-2018-12426

Install updates from vendor's website.

WP Live Chat Support - update to 8.0.07

External References

Related Security Bulletins