🔙 목록으로 돌아가기

CVE-2021-24370: WordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload

TitleWordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload
Authorpikpikcu
SeverityCritical
ImpactAttackers can upload malicious files and execute arbitrary code on the target system.
RemediationUpdate WordPress Fancy Product Designer plugin to version 4.6.9 or later to fix the vulnerability.
CVSS Score9.8
EPSS Score0.80681
CVE IDCVE-2021-24370
CWE IDCWE-434
Tags cve2021 cve wordpress wp seclists wpscan rce wp-plugin fancyproduct radykal vkev vuln

🔍 Vulnerability Description

WordPress Fancy Product Designer plugin before 4.6.9 is susceptible to an arbitrary file upload. An attacker can upload malicious files and execute code on the server, modify data, and/or gain full control over a compromised system without authentication.

🌐 HTTP Request

GET /wp-content/plugins/fancy-product-designer/inc/custom-image-handler.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) ConnectPC Safari/537.36 Browser
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24370.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24370.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A