CVE-2024-7864
13.09.2024, 06:15
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
Vendor | Product | Version |
---|---|---|
pixeljar | favicon_generator | 𝑥 < 2.1 |
pixeljar | favicon_generator | 𝑥 < 2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration