Input validation error in Shortcode Factory - CVE-2019-15322
Published: August 27, 2019
Shortcode Factory
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted URL request to specify a malicious file from the local system, obtain sensitive information or execute arbitrary code on the target Web server.
Note: In order to execute arbitrary code using a local file, the attacker would first be required to upload a malicious file or inject arbitrary commands into an existing file.