The Stylish Price List WordPress... CVE-2021-24770

4.0 AV AC AU C I A
发布: 2021-11-01
修订: 2024-11-21

The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary images.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息