vendor:
Plainview Activity Monitor
by:
LydA(c)ric Lefebvre
8.8
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: Plainview Activity Monitor
Affected Version From: 20161228
Affected Version To: 20180826
Patch Exists: YES
Related CWE: CVE-2018-15877
CPE: a:plainview_activity_monitor:plainview_activity_monitor
Platforms Tested:
2018
Plainview Activity Monitor RCE
Plainview Activity Monitor Wordpress plugin is vulnerable to OS command injection which allows an attacker to remotely execute commands on underlying system. Application passes unsafe user supplied data to ip parameter into activities_overview.php. Privileges are required in order to exploit this vulnerability, but this plugin version is also vulnerable to CSRF attack and Reflected XSS. Combined, these three vulnerabilities can lead to Remote Command Execution just with an admin click on a malicious link.
Mitigation:
Update to the fixed version 20180826