vendor:
Peugeot Music Plugin
by:
Mr.7z
8.8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Peugeot Music Plugin
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 64bit (Home Edition)
2018
WordPress Plugin Peugeot Music – Arbitrary File Upload
A vulnerability in the Peugeot Music Plugin for Wordpress allows an attacker to upload arbitrary files to the server. This is due to the lack of proper validation of the uploaded file. An attacker can exploit this vulnerability by sending a malicious file to the upload.php page via a POST request. The malicious file will then be uploaded to the server and can be accessed via the uploads directory.
Mitigation:
The vendor should ensure that all uploaded files are properly validated before being uploaded to the server.