Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12267

Опубликовано: 31 янв. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 9.1
EPSS Низкий

Описание

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:codedropz:drag_and_drop_multiple_file_upload_-_contact_form_7:*:*:*:*:*:wordpress:*:*
Версия до 1.3.8.6 (исключая)

EPSS

Процентиль: 71%
0.00661
Низкий

5.3 Medium

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 5.3
github
около 1 года назад

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.

EPSS

Процентиль: 71%
0.00661
Низкий

5.3 Medium

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-73