Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6133

Опубликовано: 15 нояб. 2023
Источник: nvd
CVSS3: 6.6
CVSS3: 4.9
EPSS Низкий

Описание

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:incsub:forminator:*:*:*:*:*:wordpress:*:*
Версия до 1.27.0 (включая)

EPSS

Процентиль: 49%
0.00258
Низкий

6.6 Medium

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.6
github
около 2 лет назад

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.

EPSS

Процентиль: 49%
0.00258
Низкий

6.6 Medium

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-434