Описание
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
Ссылки
- Permissions Required
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
- Release NotesVendor Advisory
- Permissions Required
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.2 (исключая)
cpe:2.3:a:themify:framework:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02797
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
почти 4 года назад
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
EPSS
Процентиль: 86%
0.02797
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434