The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/d91217bc-9f8f-4971-885e-89edc45b2a4d/ | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/d91217bc-9f8f-4971-885e-89edc45b2a4d/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-07-13 06:15
Updated : 2025-05-13 16:22
NVD link : CVE-2024-5450
Mitre link : CVE-2024-5450
CVE.ORG link : CVE-2024-5450
JSON object : View
Products Affected
bug_library_project
- bug_library
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
