Vulnerability Description
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Themify | Framework | < 1.2.2 |
Related Weaknesses (CWE)
References
- https://en.0day.today/exploit/22090Permissions Required
- https://packetstormsecurity.com/files/124149/WordPress-Elemin-Shell-Upload.htmlExploitThird Party AdvisoryVDB Entry
- https://themify.me/blog/updated-themify-framework-to-fix-the-vulnerabilityVendor Advisory
- https://themify.me/blog/urgent-vulnerability-found-in-themify-framework-please-rRelease NotesVendor Advisory
- https://en.0day.today/exploit/22090Permissions Required
- https://packetstormsecurity.com/files/124149/WordPress-Elemin-Shell-Upload.htmlExploitThird Party AdvisoryVDB Entry
- https://themify.me/blog/updated-themify-framework-to-fix-the-vulnerabilityVendor Advisory
- https://themify.me/blog/urgent-vulnerability-found-in-themify-framework-please-rRelease NotesVendor Advisory
FAQ
What is CVE-2013-20002?
CVE-2013-20002 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
How severe is CVE-2013-20002?
CVE-2013-20002 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2013-20002?
Check the references section above for vendor advisories and patch information. Affected products include: Themify Framework.