Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24948

Опубликовано: 03 сент. 2020
Источник: nvd
CVSS3: 7.2
CVSS2: 6.5
EPSS Средний

Описание

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:autoptimize:autoptimize:*:*:*:*:*:wordpress:*:*
Версия до 2.7.7 (исключая)

EPSS

Процентиль: 96%
0.28847
Средний

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
больше 3 лет назад

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

EPSS

Процентиль: 96%
0.28847
Средний

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434