Логотип exploitDog
bind:CVE-2021-24154
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24154

Количество 2

Количество 2

nvd логотип

CVE-2021-24154

почти 5 лет назад

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4cqh-mqrw-7qqg

больше 3 лет назад

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24154

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

CVSS3: 4.9
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4cqh-mqrw-7qqg

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу