vendor:
Advanced-Video-Embed
by:
evait security GmbH
7,5
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: Advanced-Video-Embed
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:arshmultani:advanced-video-embed-embed-videos-or-playlists
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux Apache / Wordpress 4.2.2
2016
Advanced-Video-Embed Arbitrary File Download / Unauthenticated Post Creation
A vulnerability in the Advanced-Video-Embed plugin for WordPress allows an unauthenticated attacker to download arbitrary files from the server. This is due to the lack of input validation in the ave_publishPost() function in the /inc/classes/class.avePost.php file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the admin-ajax.php file with the action parameter set to ave_publishPost and the thumb parameter set to the path of the file to be downloaded.
Mitigation:
Update to the latest version of the Advanced-Video-Embed plugin.