Описание
The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.2 (исключая)
cpe:2.3:a:ultimatemember:jobboardwp:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 96%
0.22249
Средний
7.5 High
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 7.5
github
около 3 лет назад
The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.
EPSS
Процентиль: 96%
0.22249
Средний
7.5 High
CVSS3