Логотип exploitDog
bind:CVE-2023-2068
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-2068

Количество 2

Количество 2

nvd логотип

CVE-2023-2068

больше 2 лет назад

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-6h38-5jv9-8r57

больше 2 лет назад

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-2068

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

CVSS3: 9.8
73%
Высокий
больше 2 лет назад
github логотип
GHSA-6h38-5jv9-8r57

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

CVSS3: 9.8
73%
Высокий
больше 2 лет назад

Уязвимостей на страницу