Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25082

Опубликовано: 21 фев. 2022
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Средний

Описание

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
Версия до 4.0.7 (исключая)

EPSS

Процентиль: 95%
0.19891
Средний

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
почти 4 года назад

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

EPSS

Процентиль: 95%
0.19891
Средний

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22