Логотип exploitDog
bind:CVE-2021-24222
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24222

Количество 2

Количество 2

nvd логотип

CVE-2021-24222

почти 5 лет назад

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rm26-r3rv-hxpp

больше 3 лет назад

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24222

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

CVSS3: 9.8
6%
Низкий
почти 5 лет назад
github логотип
GHSA-rm26-r3rv-hxpp

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

6%
Низкий
больше 3 лет назад

Уязвимостей на страницу