CVE-2021-24253

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:classyfrieds_project:classyfrieds:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-05-06 06:15

Updated : 2021-05-14 11:12


NVD link : CVE-2021-24253

Mitre link : CVE-2021-24253


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

classyfrieds_project

  • classyfrieds