Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8xc-86cg-8cgm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

EPSS

Процентиль: 99%
0.82734
Высокий

8.8 High

CVSS3

Дефекты

CWE-178
CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

EPSS

Процентиль: 99%
0.82734
Высокий

8.8 High

CVSS3

Дефекты

CWE-178
CWE-94