WordPress GoDAM是WordPress基金会的一款管理WordPress媒体库和文件的插件。 WordPress GoDAM 1.12.2及之前版本存在任意文件上传漏洞,该漏洞源于save_video_file()函数中的文件类型验证不足,信任攻击者提供的multipart Content-Type标头,通过wp_unique_filename()保留原始文件名,并使用$wp_filesystem->move()将原始上传移动到web服务目录,绕过了wp_handle_upload()的MIM
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rtcamp | GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more | ≤ 1.12.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rtcamp | GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more | 0 ~ 1.12.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet