SB Uploader <= 4.8 - Arbitrary File Upload
highThe SB Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the sb_uploader.php file in versions up to, and including, 4.8. This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected...
- CVSS:
- 8.8
- Affected:
- up to 4.8
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2012