Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override
Vulnerability Description
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce required to reach the upload handler is publicly exposed via wp_localize_script on any front-end page rendering the job portal shortcode, allowing unauthenticated visitors to obtain a valid nonce and bypass that gating check entirely.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
ProSolution WP Client 任意文件上传漏洞
Vulnerability Description
WordPress ProSolution WP Client是WordPress基金会的一款网站内容管理系统的客户端组件。 ProSolution WP Client 2.0.10及之前版本存在任意文件上传漏洞,该漏洞源于proSol_handleFileUpload函数未对攻击者控制的Content-Disposition头文件名进行充分验证,且保存后扩展名检查无法删除已写入文件,可能导致未经身份验证的攻击者上传可执行文件并实现远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A