CVE-2022-2381
EUVD-2022-3464815.08.2022, 11:21
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| e_unlocked_-_student_result_project | e_unlocked_-_student_result | 𝑥 ≤ 1.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration