Ver todas as ameaças

CVE-2021-24223

Alvo: Não informado

Descrição

The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it’s generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory listing enabled, accessing it is trivial.

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2021-24223
Tags
Nâo informado
Data de publicação
12/04/2021
Última atualização
08/12/2024
Pontuação em CVSS 3.0
9.8
Crítico
Rolar para cima