An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/textpattern/textpattern | product |
https://drive.google.com/drive/folders/1x55FGWZydBRxFyTVIAL1ynnk1X7gfIq9?usp=sharing | third party advisory exploit |
https://github.com/leekenghwa/CVE-2023-26852-Textpattern-v4.8.8-and- | third party advisory exploit |