Логотип exploitDog
bind:CVE-2021-24642
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24642

Количество 2

Количество 2

nvd логотип

CVE-2021-24642

больше 4 лет назад

The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mm76-wgcc-5xg2

больше 3 лет назад

The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24642

The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-mm76-wgcc-5xg2

The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу