Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qx2-wfg4-53mm

Опубликовано: 16 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

EPSS

Процентиль: 68%
0.00567
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

EPSS

Процентиль: 68%
0.00567
Низкий

8.8 High

CVSS3

Дефекты

CWE-434