Web / CMS

Authentication & Access Bypass

Upload Resume <= 1.2.0 - Captcha Bypass

Upload Resume <= 1.2.0 – Captcha Bypass The plugin does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload

5.3
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS72
PUBLISHED
2023-06-19
CVE IDs
CVE-2023-2751
VENDORS
mbbhatti
PUBLIC EXPLOIT
PoC public
CWE
CWE-639
PRODUCT
Upload Resume (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Upload Resume <= 1.2.0 – Captcha Bypass

The plugin does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.

Vulnerability details

Vulnerability details

CVE-2023-2751
CWE-639
Medium | 5.3

Upload Resume <= 1.2.0 – Captcha Bypass The plugin does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.

Auth:
None (remote)
Impact:
Limited data tampering
DISCLOSURE

Disclosure timeline

2023-03-17 Reported On

2023-05-24 Made Public On

2023-04-18 Fixed On

Credits

Yakshita Sharma