Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rx6v-3mjq-w67p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

EPSS

Процентиль: 96%
0.23388
Средний

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
больше 5 лет назад

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

EPSS

Процентиль: 96%
0.23388
Средний

Дефекты

CWE-434