cleantalk
Vulnerabilities and Security Researches

WP Business Intelligence Lite, 4b04b36974b978ce379a18f6e2f44f7f7d11e238

Published on
Mar 28, 2014
Research Description
WP Business Intelligence Lite [wp-business-intelligence-lite] < 1.3 (closed) WP Business intelligence lite < 1.3 - Arbitrary File Upload The WP Business intelligence lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ofc_upload_image.php' files in versions before 1.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected versions
max 1.3.
Status
vulnerable