vendor:
Mini Mail Dashboard Widget
by:
Ben Schmidt
9.3
CVSS
HIGH
Remote File Inclusion (RFI)
98
CWE
Product Name: Mini Mail Dashboard Widget
Affected Version From: 1.36
Affected Version To: 1.36
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:mini_mail_dashboard_widget
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Mini Mail Dashboard Widget WordPress plugin RFI
The Mini Mail Dashboard Widget Wordpress plugin is vulnerable to a Remote File Inclusion (RFI) attack. An attacker can send a malicious POST request to the wp-mini-mail.php file with an 'abspath' parameter containing a URL pointing to a malicious file. This will allow the attacker to execute arbitrary code on the vulnerable server.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application. Additionally, ensure that the application is running the latest version of the Mini Mail Dashboard Widget plugin.