Логотип exploitDog
bind:CVE-2020-24948
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-24948

Количество 2

Количество 2

nvd логотип

CVE-2020-24948

больше 5 лет назад

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-rx6v-3mjq-w67p

больше 3 лет назад

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-24948

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

CVSS3: 7.2
23%
Средний
больше 5 лет назад
github логотип
GHSA-rx6v-3mjq-w67p

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

23%
Средний
больше 3 лет назад

Уязвимостей на страницу