An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://pentest.co.uk/labs/advisory/cve-2020-7055/ | third party advisory |
https://pentest.co.uk/labs/vulnerability-disclosure-cve-2020-7055/ | third party advisory exploit |