vendor:
Audio Record
by:
Kaimi
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Audio Record
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:wordpress:audio_record:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
WordPress Plugin Audio Record 1.0 – Arbitrary File Upload
Unrestricted file upload in record upload process allowing arbitrary extension. An attacker can upload a malicious file with an arbitrary extension to the WordPress media upload directory and access it by guessing the filename if directory listing is disabled.
Mitigation:
Disable directory listing and restrict file uploads to only the allowed file types.