Record summary

CVE-2021-4436 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. VulnCheck reports CVE-2021-4436 use in known ransomware campaigns.

Description

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 4, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

3DPrint Lite

Default status: unaffected

CVE ListBefore 1.9.1.5affected

Default status: unaffected

CVE List, VulnCheckBefore 1.9.1.5affected

Nuclei templates

1
ProjectDiscoveryCRITICAL3DPrint Lite < 1.9.1.5 - Arbitrary File UploadCVSS 9.8

The plugin does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.

Impact

Unauthenticated attackers can upload arbitrary files including PHP scripts via the p3dlite_handle_upload AJAX action, potentially achieving remote code execution despite .htaccess protection.

Remediation

Fixed in 1.9.1.5

WeaknessesCWE-434
Authorss4e-io
Template tagscvecve20213dprint-litefile-uploadinstrusivewpscanwordpresswp-pluginintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wp3dprinting:3dprint_lite:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2