CVE-2021-24224
Summary
| CVE | CVE-2021-24224 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-12 14:15:00 UTC |
| Updated | 2021-04-20 00:52:00 UTC |
| Description | The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Easy-form-builder-by-bitware Project | Easy-form-builder-by-bitware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-ID-Reports/Easy Form Builder.md at e4c33529b20fa70e3a764ff9b1125839fb9900b5 · jinhuang1102/CVE-ID-Reports · GitHub | MISC | github.com | |
| Attention Required! | Cloudflare | CONFIRM | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Jin Huang
There are currently no legacy QID mappings associated with this CVE.