Description The plugin does not properly handle unauthorised files from being uploaded, only logging the issue without stopping the process, allowing unauthenticated users to upload arbitrary files to the server when the ‘Saving inquiry data in database’ settings is enabled in the plugin
CPE | Name | Operator | Version |
---|---|---|---|
eq | 5.0.2 |