PT-2023-10172 · Unknown · Vaultpress Plugin+1

CVE-2014-125104

·

Publicado

2023-06-01

·

Atualizado

2024-05-17

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VaultPress Plugin versions up to 1.6.0
Description A critical issue has been found in the VaultPress Plugin, affecting the protect aioseo ajax function of the class.vaultpress-hotfixes.php file in the MailPoet Plugin component. This issue leads to unrestricted upload and can be exploited remotely.
Recommendations For VaultPress Plugin versions up to 1.6.0, upgrade to version 1.6.1 to address this issue.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-125104

Produtos afetados

Mailpoet Plugin
Vaultpress Plugin