Логотип exploitDog
bind:CVE-2021-24123
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24123

Количество 2

Количество 2

nvd логотип

CVE-2021-24123

почти 5 лет назад

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-7cm9-xr5m-957v

больше 3 лет назад

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24123

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

CVSS3: 7.2
1%
Низкий
почти 5 лет назад
github логотип
GHSA-7cm9-xr5m-957v

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу