An attacker holding the upload_files capability (Author role or higher) can upload a file that Imagick delegates to Ghostscript for PostScript/PDF rasterization. WP_Image_Editor_Imagick::load() decided how to treat an uploaded file purely from its filename extension, so a file with an image-looking extension – or one carrying an Imagick FORMAT:... Weiterlesen
Intelligence View
Remote Code Execution via malicious file upload in WP_Image_Editor_Imagick
An attacker holding the upload_files capability (Author role or higher) can upload a file that Imagick delegates to Ghostscript for PostScript/PDF rasterization. WP_Image_Editor_Imagick::load() decided how to treat an uploaded file purely…
SOCIAL SHARE CARD GENERATOR