CVE-2022-50972
CRITICALWooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2022-50972. PoCs published by Milad karimi.
AI-analyzed exploit summary The exploit demonstrates a Remote Code Execution (RCE) vulnerability in WooCommerce v7.1.0 by injecting PHP code via the 'product-type' parameter in a GET request. The vulnerable code unsafely uses user input in a file inclusion context, allowing arbitrary PHP execution.
Description
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.
Exploits (1)
The exploit demonstrates a Remote Code Execution (RCE) vulnerability in WooCommerce v7.1.0 by injecting PHP code via the 'product-type' parameter in a GET request. The vulnerable code unsafely uses user input in a file inclusion context, allowing arbitrary PHP execution.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H