ZeroHour

CVE-2021-24663

PoC
CVSS 3.1
7.2 high
EPSS
1%p73
Published
()
Modified
Description

The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE

Vendors
simple schools staff directory project
Products
simple schools staff directory
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.