Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24490

Опубликовано: 13 сент. 2021
Источник: nvd
CVSS3: 6.8
CVSS2: 6
EPSS Низкий

Описание

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:email_artillery_project:email_artillery:*:*:*:*:*:wordpress:*:*
Версия до 4.1 (включая)

EPSS

Процентиль: 32%
0.00124
Низкий

6.8 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
больше 3 лет назад

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS

EPSS

Процентиль: 32%
0.00124
Низкий

6.8 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-352