Логотип exploitDog
bind:CVE-2021-24638
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24638

Количество 2

Количество 2

nvd логотип

CVE-2021-24638

больше 4 лет назад

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-728f-qcc4-8q48

больше 3 лет назад

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24638

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

CVSS3: 9.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-728f-qcc4-8q48

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

4%
Низкий
больше 3 лет назад

Уязвимостей на страницу