Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2p9-f4vx-cp2g

Опубликовано: 15 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.

EPSS

Процентиль: 79%
0.01315
Низкий

7.2 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
nvd
9 месяцев назад

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.

EPSS

Процентиль: 79%
0.01315
Низкий

7.2 High

CVSS3

Дефекты

CWE-78