Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-24253
HistoryMay 06, 2021 - 1:15 p.m.

Cross site request forgery (csrf)

2021-05-0613:15:00
PRIOn knowledge base
www.prio-n.com
5

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.7%

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.

CPENameOperatorVersion
classyfriedsle3.8

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.7%

Related for PRION:CVE-2021-24253