Arbitrary file upload in PowerPress Podcasting plugin by Blubrry - #VU47500

 

Arbitrary file upload in PowerPress Podcasting plugin by Blubrry - #VU47500

Published: October 12, 2020


Vulnerability identifier: #VU47500
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload. A remote administrator can upload a malicious file and execute it on the server, leading to remote code execution.


Affected software

PowerPress Podcasting plugin by Blubrry

Remediation

Install updates from vendor's website.

PowerPress Podcasting plugin by Blubrry - update to 8.3.8

External References

Related Security Bulletins