Cyclone Slider <= 3.2.0 - Authenticated (Admin+) Arbitrary File Upload
highThe Cyclone Slider Plugin is vulnerable to Remote Code Execution via the slider import functionality in versions up to, and including, 3.2.0, due to the use of the 'createfromimage' function as the sole method of validating file type. This allows authenticated users with administrative privileges to upload and extract...
- CVSS:
- 7.2
- Affected:
- up to 3.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 5, 2022