Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5267-x3g9-g6x7

Опубликовано: 15 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.

The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.

EPSS

Процентиль: 90%
0.0526
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.

EPSS

Процентиль: 90%
0.0526
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434