Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
70Vexday Risk Score
Prioriza la corrección. Ella explotación observada por VulnCheck y tiene prueba de concepto pública.
ssvc Actcvss 9.8epss 2.1%
de la publicación al arma1 días
Publicada en NVD9 nov
1ª PoC+1d
VulnCheck+251d
probabilidad de explotación
2.1%top 20% de las CVE
explotación observada
síVulnCheck
4 exploit(s) público(s)
The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files that can be leveraged for remote code execution. CVE-2024-52416 may be a duplicate of this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
eugenbobrowski · Debug ToolPoCs públicas encontradas — 4
githubgithub.com/RandomRobbieBF/CVE-2024-10586★ 1githubgithub.com/Nxploited/CVE-2024-10586-Poc★ 0vulncheckvulncheck.com/xdb/9a057c1adb0fno verificadovulncheckvulncheck.com/xdb/4d7d5c8cec4cno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.