Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fix multiple security issues
Admin
can place and execute any file via theImport Settings
option. 🟧Description
Admin
can send any file to the server anywhere.Admin
can change the codebase by sending a few requests.Steps to reproduce
Admin
..json
.Import Settings
fromrtMedia > Settings > Import/Export
section.https:/whatever.your.url/wp-content/shell.php?cmd=ls
.cmd
param.Fixes
ob_start()
function. Which executes the content in the file, no matter the extension.json_decode
andfile_get_content
functions to load the JSON data securely.Anyone can upload a file, even a
subscriber
. 🟧Description
rtmedia_api
.Steps to reproduce
sub
and passwordsub
.Any user can upload any file and place it anywhere 🟥
Steps to reproduce
Fixes
getimagesizefromstring
.