Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35627

Опубликовано: 28 дек. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 7.5
EPSS Низкий

Описание

Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the name of the image extension to PHP and executing PHP code on the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:woocommerce:gift_cards:3.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00706
Низкий

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
больше 3 лет назад

Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the name of the image extension to PHP and executing PHP code on the server.

EPSS

Процентиль: 72%
0.00706
Низкий

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434