CVE-2022-2381
15.08.2022, 11:21
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack
Vendor | Product | Version |
---|---|---|
e_unlocked_-_student_result_project | e_unlocked_-_student_result | 𝑥 ≤ 1.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration