CVE-2024-8743
MEDIUMBit File Manager < 6.5.7 - Authenticated Limited JavaScript File Upload via Improper File Type Validation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-8743. PoCs published by siunam321.
AI-analyzed exploit summary This PoC demonstrates a Limited JavaScript File Upload vulnerability in WordPress plugin Bit File Manager (CVE-2024-8743), allowing authenticated attackers with Subscriber+ access to upload malicious .css or .js files, leading to Stored XSS. The exploit includes a Flask server to exfiltrate nonces and a payload generator for CSS-based data extraction.
Description
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.
Exploits (1)
This PoC demonstrates a Limited JavaScript File Upload vulnerability in WordPress plugin Bit File Manager (CVE-2024-8743), allowing authenticated attackers with Subscriber+ access to upload malicious .css or .js files, leading to Stored XSS. The exploit includes a Flask server to exfiltrate nonces and a payload generator for CSS-based data extraction.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N