vendor:
HS Brand Logo Slider
by:
Net-Hunter
8.8
CVSS
HIGH
Authenticated File Upload Vulnerability
434
CWE
Product Name: HS Brand Logo Slider
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: N/A
CPE: a:heliossolutions:hs_brand_logo_slider:2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux Apache / Wordpress 5.5.1
2020
WordPress Plugin HS Brand Logo Slider 2.1 – ‘logoupload’ File Upload
An authenticated user can bypass the uploader of the plugin and upload arbitrary files because the extension of the uploaded file is checked on the client side.
Mitigation:
Ensure that the file upload feature is properly secured and that the file extensions are checked on the server side.