Логотип exploitDog
bind:CVE-2024-8856
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-8856

Количество 3

Количество 3

nvd логотип

CVE-2024-8856

около 1 года назад

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-wph3-vq9m-q946

около 1 года назад

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Критический
fstec логотип

BDU:2024-11396

больше 1 года назад

Уязвимость сценария UploadHandler.php плагина WP Time Capsule системы управления содержимым сайта WordPress, позволяющая нарушителю загрузить произвольные файлы, выполнить произвольный код

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-8856

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
93%
Критический
около 1 года назад
github логотип
GHSA-wph3-vq9m-q946

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
93%
Критический
около 1 года назад
fstec логотип
BDU:2024-11396

Уязвимость сценария UploadHandler.php плагина WP Time Capsule системы управления содержимым сайта WordPress, позволяющая нарушителю загрузить произвольные файлы, выполнить произвольный код

CVSS3: 9.8
93%
Критический
больше 1 года назад

Уязвимостей на страницу