Web / CMS

Remote Code Execution

Remote code execution (RCE) via Upload File bypass in Flatpress 1.2.1

Remote code execution (RCE) vulnerability in the Upload File functionality in Flatpress 1.2.1 The application has the functionality to upload images and download them further.

7.2
/ 10
High
CVSS v3.1
ADVISORY ID
PS55
PUBLISHED
2023-01-16
CVE IDs
CVE-2022-40048
VENDORS
Flatpress
PUBLIC EXPLOIT
PoC public
CWE
CWE-434
PRODUCT
FlatPress v1.2.1
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Remote code execution (RCE) vulnerability in the Upload File functionality in Flatpress 1.2.1

The application has the functionality to upload images and download them further. The

download functionality is not sandboxed, and it does not have proper security control which can be

bypassed by tricking webserver and uploading dangerous file types which leads to RCE.

Vulnerability details

Vulnerability details

CVE-2022-40048
CWE-434
High | 7.2

Remote code execution (RCE) vulnerability in the Upload File functionality in Flatpress 1.2.1 The application has the functionality to upload images and download them further.

Auth:
Administrative privileges (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2022-05-27 Reported On

2022-09-27 Made Public On

2022-10-01 Fixed On

Credits

Sandeep Wawdane