Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical vulnerability in WMPro software developed by Sunnet. The issue allows unauthenticated remote attackers to upload and execute malicious code, potentially leading to server compromise. The main concern is confirming relevance and exposure within our environment.
- Unauthenticated remote code execution via file upload.
- Critical severity with broad remote exploitation potential.
- Assess relevant systems for potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker can reach this vulnerability by interacting with the WMPro web application over the network. Since no authentication is required, an unauthenticated remote attacker can upload a web shell backdoor, leading to arbitrary code execution on the server.
- Unauthenticated remote access required.
- Upload a web shell backdoor.
- Arbitrary code execution on server.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability in WMPro could allow an unauthenticated remote attacker to upload and execute web shell backdoors. This could lead to arbitrary code execution on the server when the product is exposed to the network.
- Arbitrary code execution on the server.
- Upload and execute web shell backdoors.
- Unauthenticated remote attackers can exploit.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WMPro application, developed by Sunnet, presents a critical Arbitrary File Upload vulnerability that demands immediate attention from infrastructure and application owners. The first actionable step involves pinpointing all WMPro deployments, assessing their network exposure, confirming business criticality, and identifying the specific team accountable for remediation to establish a risk-based action plan.
- Identify WMPro deployments and owners.
- Verify external reachability and business impact.
- Plan remediation or mitigation actions.