Description
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the server.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Lenon Leite
References
www.exploit-db.com/exploits/44432 (ExploitDB-44432)
lenonleite.com.br/ (Official Product Homepage)
www.vulncheck.com/...ustom-fields-type-remote-code-execution (VulnCheck Advisory: BuddyPress Xprofile Custom Fields Type 2.6.3 Remote Code Execution)