CVE-2021-24254

CVE-2021-24254

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

Source: CVE-2021-24254

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다