Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q5w-5rhq-cpgp

Опубликовано: 27 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

EPSS

Процентиль: 74%
0.00811
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
больше 3 лет назад

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

EPSS

Процентиль: 74%
0.00811
Низкий

7.2 High

CVSS3

Дефекты

CWE-434