CVE-2021-24563
11.10.2021, 11:15
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Vendor | Product | Version |
---|---|---|
frontend_uploader_project | frontend_uploader | 𝑥 ≤ 1.3.2 |
𝑥
= Vulnerable software versions
References