vendor:
Add From Server
by:
Summer of Pwnage
7,5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Add From Server
Affected Version From: 6.2
Affected Version To: 6.2
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:add_from_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Cross-Site Request Forgery vulnerability in Add From Server WordPress Plugin
It was discovered that Add From Server is vulnerabile to Cross-Site Request Forgery. It can be exploited by luring the target user into clicking a specially crafted link or visiting a malicious website (or advertisement). An attacker can use this issue to add illegal content to the victims server, or add very large files to the victim's server to exaust the amount of avalible disk space.
Mitigation:
This issue is resolved in Add From Server version 3.3.2.