CVE-2018-25325
HIGHWoocommerce CSV Importer 3.3.6 Path Traversal File Deletion
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25325. PoCs published by Lenon Leite.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file deletion vulnerability in the Woocommerce CSV importer plugin (version 3.3.6) due to improper sanitization of the 'filename' parameter in the 'delete_export_file' AJAX action. An authenticated user can delete critical files like 'wp-config.php' by submitting a crafted POST request.
Description
Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete sensitive files like wp-config.php outside the intended export directory.
Exploits (1)
This exploit demonstrates an arbitrary file deletion vulnerability in the Woocommerce CSV importer plugin (version 3.3.6) due to improper sanitization of the 'filename' parameter in the 'delete_export_file' AJAX action. An authenticated user can delete critical files like 'wp-config.php' by submitting a crafted POST request.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N