Логотип exploitDog
bind:CVE-2023-5957
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-5957

Количество 2

Количество 2

nvd логотип

CVE-2023-5957

около 2 лет назад

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-mqv9-v5xg-xp9h

около 2 лет назад

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-5957

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

CVSS3: 7.2
1%
Низкий
около 2 лет назад
github логотип
GHSA-mqv9-v5xg-xp9h

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

CVSS3: 7.2
1%
Низкий
около 2 лет назад

Уязвимостей на страницу