Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mh6-g78c-5h6c

Опубликовано: 16 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

EPSS

Процентиль: 38%
0.00166
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

EPSS

Процентиль: 38%
0.00166
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79