The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server
Metrics
Affected Vendors & Products
References
History
Fri, 27 Sep 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:* |
Fri, 13 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pixeljar
Pixeljar favicon Generator |
|
CPEs | cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:*:*:* | |
Vendors & Products |
Pixeljar
Pixeljar favicon Generator |
|
Metrics |
cvssV3_1
|
Fri, 13 Sep 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server | |
Title | Favicon Generator < 2.1 - Arbitrary File Upload via CSRF | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-09-13T06:00:04.133Z
Updated: 2024-09-13T14:27:56.345Z
Reserved: 2024-08-15T18:43:39.788Z
Link: CVE-2024-7863
Vulnrichment
Updated: 2024-09-13T14:23:43.047Z
NVD
Status : Analyzed
Published: 2024-09-13T06:15:15.650
Modified: 2024-09-27T21:27:07.640
Link: CVE-2024-7863
Redhat
No data.