The Sermon Browser WordPress plugin... CVE-2022-0499

6.8 AV AC AU C I A
发布: 2022-03-28
修订: 2024-11-21

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息