cleantalk
Vulnerabilities and Security Researches

Super Progressive Web Apps, 4fd989ae-db35-40fa-ba61-b2d4fbb3994d

Published on
-
Research Description
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.12 Super Progressive Web Apps &lt; 2.1.12 - Authenticated (Low Privileged) Arbitrary File Upload to RCE When the Apple Touch Icons &amp; Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, does not properly check for CSRF, authorisation and the content of the uploaded archive file. This allows attackers to upload an archive with a PHP file, leading to RCE by either using a low privilege account (subscriber+) or a CSRF attack on any logged in user. v2.1.11 fixed the CSRF check, only. v2.1.12 added capability check.
Affected versions
max 2.1.12.
Status
vulnerable