Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-34639
HistoryAug 05, 2021 - 9:15 p.m.

Unrestricted file upload

2021-08-0521:15:00
PRIOn knowledge base
www.prio-n.com
2

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. “payload.php.png” which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.

CPENameOperatorVersion
wordpress_download_managerle3.1.24

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

Related for PRION:CVE-2021-34639