Описание
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server
Ссылки
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.1 (исключая)
cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 42%
0.00197
Низкий
6.8 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.1
github
больше 1 года назад
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server
EPSS
Процентиль: 42%
0.00197
Низкий
6.8 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-352