WordPress Mobile App Builder By Wappress Plugin Arbitrary File Upload Vulnerability



The Mobile App Builder By Wappress plugin for WordPress is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.

An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access to the application; other attacks are also possible.

Mobile App Builder By Wappress 1.05 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 96905
Class: Input Validation Error
CVE: CVE-2017-1002000
CVE-2017-1002001

Remote: Yes
Local: No
Published: Mar 06 2017 12:00AM
Updated: Apr 12 2019 10:00PM
Credit: Larry W. Cashdollar
Vulnerable: WordPress mobile-app-builder-by-wappress 1.05


Not Vulnerable:

Exploit


Attackers can exploit this issue through a browser.


Related Posts