CVE-2021-24890
Summary
| CVE | CVE-2021-24890 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-26 13:15:00 UTC |
| Updated | 2022-09-28 16:47:00 UTC |
| Description | The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file |
Risk And Classification
Problem Types: CWE-352 | CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dplugins | Scripts Organizer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Scripts Organizer < 3.0 - Unauthenticated Arbitrary File Upload WordPress Security Vulnerability | CONFIRM | wpscan.com | |
| Scripts Organizer | dplugins.com | MISC | dplugins.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ovidiu Maghetiu
There are currently no legacy QID mappings associated with this CVE.