Логотип exploitDog
bind:CVE-2021-24254
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24254

Количество 2

Количество 2

nvd логотип

CVE-2021-24254

почти 5 лет назад

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xmhj-gj46-9j4f

больше 3 лет назад

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24254

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

CVSS3: 7.2
1%
Низкий
почти 5 лет назад
github логотип
GHSA-xmhj-gj46-9j4f

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу