nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-5604 CVE-2023-5604
CRITICAL
Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2023-5604 has a selected CVSS score of 9.8 (critical).
Description
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 11, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Asgaros ForumDefault status: unaffected | CVE List | Before 2.7.1 | affected |
asgaros_forumBrowse asgaros / asgaros_forumDefault status: unknown | CVE List | Before 2.71 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/4ce69d71-87bf-4d95-90f2-63d558c78b69