Summary
ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.
Risk profile
6.5 · M E D I U M
CVSS assessment
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack vector
- N E T W O R K
- Complexity
- L O W
- Privileges
- L O W
- User interaction
- N O N E
- Scope
- U N C H A N G E D
- Confidentiality
- N O N E
- Integrity
- N O N E
- Availability
- H I G H
Weaknesses
-
Uncontrolled Resource Consumption
CWE-400
Configurations
1
configuration
Affected products
Vulnerable match
cpe:2.3:a:processwire:processwire:*:*:*:*:*:*:*:*
Through 3.0.246
inclusive
Further reading
2
sources