Description
The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.
Published: 2021-05-05
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-11168 The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.
History

No history.

Subscriptions

College Publisher Import Project College Publisher Import
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:28:22.246Z

Reserved: 2021-01-14T00:00:00.000Z

Link: CVE-2021-24254

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-06T13:15:11.833

Modified: 2024-11-21T05:52:41.750

Link: CVE-2021-24254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses