cleantalk
Vulnerabilities and Security Researches

Super Progressive Web Apps, fd1f0cee-44e7-4847-a53d-e54844399fd1

Published on
-
Research Description
Super Progressive Web Apps [super-progressive-web-apps] < 2.1.13 Super Progressive Web Apps &lt; 2.1.13 - Authenticated (High Privileged) Arbitrary File Upload to RCE When the Apple Touch Icons &amp; Splash Screen add-on is active, its superpwa_splashscreen_uploader AJAX action, did not properly check for authorisation and the content of the uploaded archive file. This allows high privilege users (admin+) to upload an archive with a PHP file, leading to RCE. v2.1.12 attempted to fix the issue by deleting potential malicious files, after extracting the archive, but was checking the wrong folder. And even if the correct folder was checked, a race condition could have been used to exploit the issue
Affected versions
max 2.1.13.
Status
vulnerable