ZeroHour

CVE-2024-10098

PoC
CVSS 3.1
2.7 low
EPSS
<1%p34
Published
()
Modified
Description

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

Vendors
spiderteams
Products
applyonline - application form builder and manager
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.