cleantalk
Vulnerabilities and Security Researches

Orbit Fox by ThemeIsle, 014073fa-7949-49e8-996f-2f84dab94ba9

Published on
-
Research Description
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts &amp; More [themeisle-companion] < 2.6.4 Orbit Fox by ThemeIsle &lt;= 2.6.3 -Does not properly Authenticate REST API Calls Orbit Fox by Themeisle (aka Themeisle Companion) version &lt;= 2.6.3 does not properly authenticate REST API calls allowing unauthenticated users to execute several API calls. In some cases one of these calls can be used to upload arbitrary files which can lead to remote code execution.
Affected versions
max 2.6.4.
Status
vulnerable