vendor:
Wordpress N-Media Website Contact Form with File Upload
by:
Claudio Viviani
7.5
CVSS
HIGH
Unrestricted File Upload
434
CWE
Product Name: Wordpress N-Media Website Contact Form with File Upload
Affected Version From: 1.3.2004
Affected Version To: 1.3.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wordpress
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 1.1.0a / Curl 7.26.0
2015
WordPress N-Media Website Contact Form with File Upload 1.3.4
The 'upload_file()' ajax function in Wordpress N-Media Website Contact Form with File Upload 1.3.4 is affected from unrestircted file upload vulnerability, allowing an attacker to upload a malicious file to the server.
Mitigation:
Ensure that the application validates the file type and size of the uploaded file before allowing it to be uploaded to the server.