CVE-2015-4455: Malicious File Upload
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gformaviary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4455?
CVE-2015-4455 is considered a critical vulnerability due to its ability to allow remote code execution.
How can I fix CVE-2015-4455?
To fix CVE-2015-4455, update the Aviary Image Editor Add-on for Gravity Forms plugin to the latest version that addresses this vulnerability.
What type of attack is possible with CVE-2015-4455?
CVE-2015-4455 allows for arbitrary code execution through unrestricted file uploads, enabling attackers to upload and execute malicious files.
Which versions are affected by CVE-2015-4455?
CVE-2015-4455 affects version 3.0 beta and below of the Aviary Image Editor Add-on for Gravity Forms plugin.
Is there any known exploit for CVE-2015-4455?
Yes, there are known exploits for CVE-2015-4455 that allow attackers to exploit the file upload functionality to run arbitrary code.