vendor:
RSS News AutoPilot Script
by:
Arbin Godar
9,3
CVSS
HIGH
Cross-Site Request Forgery (CSRF) to Persistent Cross-Site Scripting (XSS) and Remote Code Execution (RCE) Through Unrestricted File Upload
352
CWE
Product Name: RSS News AutoPilot Script
Affected Version From: 1.0.1
Affected Version To: 3.0.3
Patch Exists: NO
Related CWE: N/A
CPE: a:codecanyon:rss_news_autopilot_script
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
RSS News AutoPilot Script 1.0.1 / 3.0.3 – CSRF to Persistent XSS and RCE Through Unrestricted File Upload
An Attackers are able to execute js and php code on web application using RSS News - AutoPilot Script which allow an attacker to create a post when an authenticated user/admin browses a special crafted web page. Also, all the process was possible without any authenticated user/admin for more info watch the below PoC Video.
Mitigation:
The title parameter should be filtered for special characters and the file type should be filtered while uploading images.