The Popup Builder WordPress plugin... CVE-2021-25082

6.5 AV AC AU C I A
发布: 2022-02-21
修订: 2024-11-21

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

0%
暂无可用Exp或PoC
当前有1条受影响产品信息