Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wvhv-jqpm-79vj

Опубликовано: 04 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server

EPSS

Процентиль: 92%
0.07544
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server

CVSS3: 5.3
nvd
больше 3 лет назад

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server

EPSS

Процентиль: 92%
0.07544
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862