Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upload form allowed to all users bug #4842

Closed
anonymous-matomo-user opened this issue Mar 11, 2014 · 1 comment
Closed

Upload form allowed to all users bug #4842

anonymous-matomo-user opened this issue Mar 11, 2014 · 1 comment
Labels
Bug For errors / faults / flaws / inconsistencies etc. Critical Indicates the severity of an issue is very critical and the issue has a very high priority. worksforme The issue cannot be reproduced and things work as intended.

Comments

@anonymous-matomo-user
Copy link

Hello , I found a upload form that is shown to any user.
We can even upload files without getting access to a panel ..
Here is the upload form :
http://crowdfunding.piwik.org/wp-content/plugins/ignitiondeck/templates/admin/_productForm.php

A malicious attacker could use this to upload a malicious PHP script then he will take control of your website..

Please make sure you patch it & answering me.
Keywords: bug upload hacker

@mattab
Copy link
Member

mattab commented Mar 12, 2014

I couldn't find that the form uploads a file. It seems it just reloads the page without uploading the file. Thanks for the report! See http://piwik.org/security/

This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug For errors / faults / flaws / inconsistencies etc. Critical Indicates the severity of an issue is very critical and the issue has a very high priority. worksforme The issue cannot be reproduced and things work as intended.
Projects
None yet
Development

No branches or pull requests

2 participants