Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7hj-68jp-pg28

Опубликовано: 07 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

EPSS

Процентиль: 31%
0.00121
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
больше 1 года назад

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

EPSS

Процентиль: 31%
0.00121
Низкий

4.8 Medium

CVSS3