Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvv9-757j-qvmm

Опубликовано: 28 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

EPSS

Процентиль: 99%
0.73672
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-352
CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

EPSS

Процентиль: 99%
0.73672
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-352
CWE-434