The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:21:18.724Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24222

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-12T14:15:15.633

Modified: 2024-11-21T05:52:37.700

Link: CVE-2021-24222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.