Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6rj-wrr3-48q3

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

EPSS

Процентиль: 99%
0.7051
Высокий

Дефекты

CWE-284

Связанные уязвимости

nvd
около 11 лет назад

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

EPSS

Процентиль: 99%
0.7051
Высокий

Дефекты

CWE-284