Логотип exploitDog
bind:CVE-2024-9290
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9290

Количество 3

Количество 3

nvd логотип

CVE-2024-9290

около 1 года назад

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-w38j-p59r-qv5r

около 1 года назад

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2025-00174

больше 1 года назад

Уязвимость функции ibk_restore_migrate_check() плагина Super Backup & Clone (WP SuperBackup) системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-9290

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
69%
Средний
около 1 года назад
github логотип
GHSA-w38j-p59r-qv5r

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
69%
Средний
около 1 года назад
fstec логотип
BDU:2025-00174

Уязвимость функции ibk_restore_migrate_check() плагина Super Backup & Clone (WP SuperBackup) системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
69%
Средний
больше 1 года назад

Уязвимостей на страницу