CVE-2021-25082

CVE-2021-25082

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

Source: CVE-2021-25082

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다