vendor:
WEBIGniter
by:
nu11secur1ty
9
CVSS
CRITICAL
File Upload Remote Code Execution
CWE
Product Name: WEBIGniter
Affected Version From: WEBIGniter v28.7.23
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: None
2023
WEBIGniter v28.7.23 File Upload – Remote Code Execution
The media function in WEBIGniter v28.7.23 is vulnerable to file upload, allowing an attacker to upload and execute PHP files remotely. This can lead to malicious activities on the server.
Mitigation:
It is recommended to apply a patch or update to a version that fixes the file upload vulnerability. Additionally, implement proper input validation and file type checking to prevent unauthorized file uploads.