Arbitrary file upload in WPS Bidouille - #VU19346
Published: July 24, 2019
WPS Bidouille
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file uploads in the "/classes/suggest-plugins-themes.php" file. A remote administrator can change the URL that will be passed in the uploader of "download_package()" and upload and execute arbitrary file on the server.