The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server
History

Fri, 27 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CPEs cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:*

Fri, 13 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Pixeljar
Pixeljar favicon Generator
CPEs cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:*:*:*
Vendors & Products Pixeljar
Pixeljar favicon Generator
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server
Title Favicon Generator < 2.1 - Arbitrary File Upload via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-13T06:00:04.133Z

Updated: 2024-09-13T14:27:56.345Z

Reserved: 2024-08-15T18:43:39.788Z

Link: CVE-2024-7863

cve-icon Vulnrichment

Updated: 2024-09-13T14:23:43.047Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-13T06:15:15.650

Modified: 2024-09-27T21:27:07.640

Link: CVE-2024-7863

cve-icon Redhat

No data.