Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpqx-2jhq-wrpw

Опубликовано: 06 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon allows Upload a Web Shell to a Web Server.This issue affects Drop Uploader for CF7 - Drag&Drop File Uploader Addon: from n/a through <= 2.4.1.

Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon allows Upload a Web Shell to a Web Server.This issue affects Drop Uploader for CF7 - Drag&Drop File Uploader Addon: from n/a through <= 2.4.1.

EPSS

Процентиль: 20%
0.00064
Низкий

10 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 10
nvd
3 месяца назад

Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon allows Upload a Web Shell to a Web Server.This issue affects Drop Uploader for CF7 - Drag&Drop File Uploader Addon: from n/a through <= 2.4.1.

EPSS

Процентиль: 20%
0.00064
Низкий

10 Critical

CVSS3

Дефекты

CWE-434