CVE-2021-24563
EUVD-2021-1147511.10.2021, 11:15
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frontend_uploader_project | frontend_uploader | 𝑥 ≤ 1.3.2 |
𝑥
= Vulnerable software versions
References