SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload
Vulnerability Description
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4225
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- pang0lin @webray.com.cn inc
References
More from Unknown
View All →Affected Vendor
Unknown
View all reports →