Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvjm-6792-4mj3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

EPSS

Процентиль: 99%
0.7493
Высокий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

CVSS3: 9.8
fstec
почти 5 лет назад

Уязвимость плагина для загрузки изображений Imagements системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.7493
Высокий

Дефекты

CWE-434