Web / CMS

Authentication & Access Bypass

Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass

Drag and Drop Multiple File Upload < 1.3.6.5 – File Upload Size Limit Bypass The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when…

4.3
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS64
PUBLISHED
2023-01-06
CVE IDs
CVE-2022-3282
VENDORS
Codedropz
PUBLIC EXPLOIT
PoC public
CWE
CWE-639
PRODUCT
Drag and Drop Multiple File Upload (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Drag and Drop Multiple File Upload < 1.3.6.5 – File Upload Size Limit Bypass

The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

Vulnerability details

Vulnerability details

CVE-2022-3282
CWE-639
Medium | 4.3

Drag and Drop Multiple File Upload < 1.3.6.5 – File Upload Size Limit Bypass The plugin does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form.

Auth:
Any authenticated user (remote)
Impact:
Limited data tampering
DISCLOSURE

Disclosure timeline

2022-08-26 Reported On

2022-09-23 Made Public On

2022-09-23 Fixed On

Credits

Sanjay Das