Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vx2x-wm5h-864r

Опубликовано: 16 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

EPSS

Процентиль: 91%
0.07236
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

EPSS

Процентиль: 91%
0.07236
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434