CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-25913

Medium Severity
SVRS
30/100

CVSSv3
NA/10

EPSS
0.00569/1

CVE-2024-25913: Unrestricted File Upload Vulnerability in Skymoonlabs MoveTo allows attackers to upload dangerous file types. This issue affects MoveTo versions up to 6.2, potentially leading to remote code execution. The CVSS score is 0, however, the SVRS of 30 indicates a low but existing risk based on real-world threat intelligence. While not critical, exploiting this vulnerability could compromise system integrity. The CWE-434 issue highlights the danger of allowing users to upload arbitrary files without proper validation. Addressing this is important as it has been tagged "In The Wild".

In The Wild
2024-02-26

2024-02-26
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-25913 is an Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo. This vulnerability allows an attacker to upload a file with a dangerous type, which could lead to remote code execution. The CVSS score for this vulnerability is 10, indicating that it is a critical vulnerability that requires immediate attention. However, the SOCRadar Vulnerability Risk Score (SVRS) for this vulnerability is 0, indicating that it is not currently being actively exploited by threat actors.

Key Insights

  • This vulnerability could allow an attacker to execute arbitrary code on a vulnerable system.
  • The vulnerability affects MoveTo versions from n/a through 6.2.
  • There are no known active exploits for this vulnerability.
  • The Cybersecurity and Infrastructure Security Agency (CISA) has not issued a warning for this vulnerability.

Mitigation Strategies

  • Update MoveTo to version 6.3 or later.
  • Restrict file uploads to only allowed file types.
  • Implement a web application firewall (WAF) to block malicious requests.
  • Monitor your systems for suspicious activity.

Additional Information

If you have any additional questions about this incident, you can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

No tweets found for this CVE

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://patchstack.com/database/vulnerability/moveto/wordpress-moveto-plugin-6-2-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve

CWE Details

CWE IDCWE NameDescription
CWE-434Unrestricted Upload of File with Dangerous TypeThe software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence