Vulnerability CVE-2023-2359


Published: 2023-06-19

Description:
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
exploit Slider Revolution <= 6.6.12 - Authenticated (Administrator+) Arbitrary File Upload
e1.coders
29.10.2023

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

 References:
https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65

Copyright 2024, cxsecurity.com

 

Back to Top