Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grjr-768v-vmjf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

EPSS

Процентиль: 99%
0.67223
Средний

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

EPSS

Процентиль: 99%
0.67223
Средний

Дефекты

CWE-434