Super Progressive Web Apps, 4fd989ae-db35-40fa-ba61-b2d4fbb3994d
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- Super Progressive Web Apps [super-progressive-web-apps] < 2.1.12 Super Progressive Web Apps < 2.1.12 - Authenticated (Low Privileged) Arbitrary File Upload to RCE When the Apple Touch Icons & Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, does not properly check for CSRF, authorisation and the content of the uploaded archive file. This allows attackers to upload an archive with a PHP file, leading to RCE by either using a low privilege account (subscriber+) or a CSRF attack on any logged in user. v2.1.11 fixed the CSRF check, only. v2.1.12 added capability check.
- Affected versions
-
max 2.1.12.
- Status
-
vulnerable