Логотип exploitDog
bind:CVE-2021-24890
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24890

Количество 2

Количество 2

nvd логотип

CVE-2021-24890

больше 3 лет назад

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-73qx-mm4g-5qj8

больше 3 лет назад

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24890

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-73qx-mm4g-5qj8

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу