Логотип exploitDog
bind:CVE-2023-0039
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-0039

Количество 2

Количество 2

nvd логотип

CVE-2023-0039

около 3 лет назад

Rejected reason: Duplicate. Please use CVE-2022-4060 instead.

EPSS: Низкий
github логотип

GHSA-7gm9-w486-54r3

около 3 лет назад

The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command execution due to the use of a nopriv AJAX action and user supplied function calls and parameters in versions up to, and including 2.19. This makes it possible for unauthenticated attackers to call arbitrary PHP functions and perform actions like adding new files that can be webshells and updating the site's options to allow anyone to register as an administrator.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-0039

Rejected reason: Duplicate. Please use CVE-2022-4060 instead.

около 3 лет назад
github логотип
GHSA-7gm9-w486-54r3

The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command execution due to the use of a nopriv AJAX action and user supplied function calls and parameters in versions up to, and including 2.19. This makes it possible for unauthenticated attackers to call arbitrary PHP functions and perform actions like adding new files that can be webshells and updating the site's options to allow anyone to register as an administrator.

CVSS3: 9.8
около 3 лет назад

Уязвимостей на страницу