Exploit Report

Computer Security And Bug Information

CVE-2021-24890

CVECVE-2021-24890
CVE Ordinal Value199652
Published Date2022-09-26T13:15Z
Modified Date2022-09-28T16:47Z
CWE TypeCWE-352
CVSS 3.xCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
DescriptionThe Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://dplugins.com/products/scripts-organizer/
Reference DescriptionMISC https://dplugins.com/products/scripts-organizer/
Reference URLhttps://wpscan.com/vulnerability/f3b450d2-84ce-4c13-ad6a-b60785dee7e7
Reference DescriptionCONFIRM https://wpscan.com/vulnerability/f3b450d2-84ce-4c13-ad6a-b60785dee7e7
TagsProduct
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles