GHSA-77f2-mm55-xvp4HighCVSS 8.8
TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can authenticate, retrieve a CSRF token from the plugin event page, and upload malicious PHP files to the textpattern/tmp/ directory for code execution.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2021-47976
- https://github.com/textpattern/textpattern
- https://textpattern.com
- https://www.exploit-db.com/exploits/50095
- https://www.vulncheck.com/advisories/textpattern-cms-dev-authenticated-remote-code-execution-via-plugin-upload
- https://github.com/advisories/GHSA-77f2-mm55-xvp4