CVE-2021-24890

CVE-2021-24890

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

Source: CVE-2021-24890

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다