Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgmv-5488-h5p5

Опубликовано: 31 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.

EPSS

Процентиль: 71%
0.00661
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-73
CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.

EPSS

Процентиль: 71%
0.00661
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-73
CWE-862