Логотип exploitDog
bind:CVE-2021-24563
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24563

Количество 2

Количество 2

nvd логотип

CVE-2021-24563

почти 4 года назад

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-287r-36rw-cfgc

около 3 лет назад

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24563

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

CVSS3: 6.1
30%
Средний
почти 4 года назад
github логотип
GHSA-287r-36rw-cfgc

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

30%
Средний
около 3 лет назад

Уязвимостей на страницу