Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-287r-36rw-cfgc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

EPSS

Процентиль: 96%
0.29956
Средний

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

EPSS

Процентиль: 96%
0.29956
Средний

Дефекты

CWE-79